winrar setup.exe

WeDownload, Ltd

The application winrar setup.exe by WeDownload has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the Midia Downloader installer. With this installer, users are expecting to download WinRAR archiver but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware. The file has been seen being downloaded from winrar.xtremedownload.com.
Publisher:
WeDownload, Ltd  (signed and verified)

MD5:
e09931a0209619e25a9ffc777b19c8fb

SHA-1:
5cffd04441ad8027795b7f84d4ca7ce76266da87

SHA-256:
b43f3233ba1f1239bd8db7e290891fb51fe76188f72c9e7852ba13868c620fdf

Scanner detections:
14 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 10:53:50 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Soft32Downloader
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.166.108

avast!
Downloader-TOV [PUP]
2014.9-140806

AVG
Wedownload
2015.0.3390

ESET NOD32
MSIL/Soft32Downloader.C potentially unwanted application
8.7.0.302.0

G Data
Win32.Application.Soft32Downloader
14.8.24

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.3446

McAfee
Trojan.Artemis!0BC7F2EDE6A3
5600.7046

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Reason Heuristics
PUP.Installer.WeDownload.M
14.8.7.20

Trend Micro House Call
Suspici.9E5A9E81
7.2.218

Vba32 AntiVirus
Signed-AdWare.WeDownload
3.12.26.3

VIPRE Antivirus
Threat.4150696
31208

File size:
779 KB (797,736 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Midia Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\winrar setup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
2/5/2013 10:00:00 PM

Valid to:
2/11/2016 10:00:00 AM

Subject:
CN="WeDownload, Ltd", O="WeDownload, Ltd", L=Nicosia, C=CY

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0320C5B8F7CE6E92D3665598826A4480

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:gwMDD47E2/bDlvNXK6si6xhMiprWebxTAij1rlAUN4Cvt0RUli/F2mt:gtg7E2NvJAv/dqIxLjAUVl0RUlGYm

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file winrar setup.exe has been seen being distributed by the following URL.

Remove winrar setup.exe - Powered by Reason Core Security