winzip installer.exe

WinZip Computing LLC

The application winzip installer.exe by WinZip Computing has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.2016delivery33.com.
Publisher:
WinZip  (signed by WinZip Computing LLC)

Product:
WinZip

Version:
1.0.8.36099

MD5:
53f3adc370665c405c56ee3a9431ce78

SHA-1:
64ba6dd221bbda159730b06b064fb713fe1966c8

SHA-256:
8036fe58fa037dd77fa7debe1ad03d64fbc1a94f1f62e2d0a81160fe6d70c862

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/6/2024 6:41:04 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.InstallCore.1903
9.0.1.091

ESET NOD32
Win32/InstallCore.OZ potentially unwanted (variant)
10.13257

Fortinet FortiGate
Riskware/InstallCore
3/31/2016

Reason Heuristics
PUP.InstallCore.ENG (M)
16.3.31.18

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16329

File size:
1.2 MB (1,212,384 bytes)

Product version:
1.0.8.36099

Copyright:
WinZip

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\winzip%20installer.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
12/29/2015 4:00:00 PM

Valid to:
3/30/2017 4:59:59 PM

Subject:
CN=WinZip Computing LLC, OU=IT, O=WinZip Computing LLC, L=Mansfield, S=Connecticut, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
0DF50E7B70B5921CAD5206E96DBE05E8

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:vfFadHPKqNplIRlRIOotvX2x+uEgOUJ9d5aQDcsAEilYBxxtugux2TrhbICw:vtcHPKqNClRK4jHhYQYsiYVtvq2TdbIp

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8906

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file winzip installer.exe has been seen being distributed by the following URL.

http://www.2016delivery33.com/c?x=ETb8Z/brhNdh0Ca8r7F59JCgx89hvfOuwgd0sZA/IAo=&c=5Zc GkDjJfzlRSxup6tnnVUdgCfaE/5y0khTAX7soa7H9umi6wlTJuJkCHXYoxSA3WBMExLqC 2TJxfV 542gcXLWFniLFrbjYAWh7iRH1azkj5koZ3EuV4lrRM4fIv nWlErq8g2tjN Llti2zwxQPh8f06MRamFQkufgr SWQ=&e=0&downloadAs=WinZip Installer&fallback_url=http://download.winzip.com/gl/.../winzip20-home.exe

Remove winzip installer.exe - Powered by Reason Core Security