winrar_setup.exe

The application winrar_setup.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from www.startsdownload.com.
MD5:
bc9bdee37de2332978763d4828cac595

SHA-1:
55659e63b52c2cec69eb1fc80249f583b19e6fd7

SHA-256:
f2626e1f8edc5ab4cda855f0e70454c768d0748d516b3b5c903c60d5241d15b9

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
Uses the Solimba installer to bundle adware offers.

Analysis date:
4/20/2024 3:27:16 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Win.Reputation
15.10.11.16

Trend Micro House Call
HV_ZYX_CA083374.TOMC
7.2.56

Vba32 AntiVirus
Worm.Koobface.rtz
3.12.20.2

VIPRE Antivirus
No Threat: Solimba
15874

File size:
396.7 KB (406,251 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\winrar_setup.exe

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:VslgK1bZ4Y+JQikkbavH2t+E9vxEfARxXO28k69EgX2ubBhaEig40HMT5yBgOKEF:4X6YYZbN+8pEfAbp6EmliQHMVyB/z

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9029

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file winrar_setup.exe has been seen being distributed by the following URL.

Remove winrar_setup.exe - Powered by Reason Core Security