winrar_dsetup.exe

META., JSC

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application winrar_dsetup.exe by META., JSC has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. With this installer, users are expecting to download WinRAR archiver but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
META., JSC  (signed and verified)

MD5:
10d8cdb58e407a6a2e11d104855efff5

SHA-1:
5b339328095652496ee465eeba108230e3ac56da

SHA-256:
bd3e15f2ee9b46ec811625d9b15d8e75590854fe3651dbeb226933cbe7be00ac

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/27/2024 12:55:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.METAJSC.Installer (M)
16.2.15.15

File size:
617.6 KB (632,448 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/5/2013 4:00:00 PM

Valid to:
11/5/2016 4:59:59 PM

Subject:
CN="META., JSC", O="META., JSC", STREET="B49, Duy Tan Street, Dich Vong Hau Ward, Cau Giay District", L=Hanoi, S=Hanoi, PostalCode=10000, C=VN

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D08397D094A2AC46809B3100D8A03A0A

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:93ErMJfsG0G6V6jmxtDIAy34ZOuPZDpBBBvwJmwZe3JH16KnKhZW8FIly:932MJfsDlV6jmxByruP3BBBYJJEJH16Q

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.7821

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

Remove winrar_dsetup.exe - Powered by Reason Core Security