2ddfa00cf7d066d9e34fe01da6118546d1a941a0

Statscom

This is the Tightrope WebInstall which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file 2ddfa00cf7d066d9e34fe01da6118546d1a941a0 by Statscom has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Tightrope WebInstall installer. It is installed within the Mozilla Firefox web browser as part of an addin/plugin.
Publisher:
Statscom  (signed and verified)

Product:
Statscom

Version:
76.3.8.2514

MD5:
a2882c62dc5e4f9ea25578e60a51709b

SHA-1:
8f2141e71fe62aff2898eec659bb404fe5cf79ca

SHA-256:
1a49b45319adc842185c6ef17ab034527e07740f113fac0379dbadf687e923f4

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/26/2024 12:51:56 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Tightrope.Statscom.Bundler (M)
16.1.5.22

File size:
1 MB (1,049,078 bytes)

Product version:
76.3.8.2514

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

Bundler/Installer:
Tightrope WebInstall

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\mozilla\firefox\profiles\{user}.default\cache2\entries\2ddfa00cf7d066d9e34fe01da6118546d1a941a0

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
11/11/2015 11:21:38 AM

Valid to:
9/16/2016 5:36:38 PM

Subject:
CN=Statscom, O=Statscom, L=San Francisco, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00B76A917B400E54E5

File PE Metadata
Compilation timestamp:
10/27/2014 1:54:47 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:8w0FSNT9oqE8+JJ//n6XxIPwH8DpatBn4m3LR1BR1N0hzX4c1LGHb531Sn0h9J:pNT2RJp6BLHapaYm7R1/4zogGHl1c0hf

Entry address:
0x18AA

Entry point:
E8, F1, C3, 00, 00, E9, F5, BC, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 81, EC, 1C, 02, 00, 00, 53, 55, 8B, AC, 24, 28, 02, 00, 00, 56, 57, 6A, 01, 55, E8, E7, 5C, 00, 00, 8B, F0, 89, 44, 24, 18, 8D, 44, 24, 1C, 50, 6A, 00, 6A, 02, 55, C7, 44, 24, 2C, 00, 00, 00, 00, E8, 8A, 5E, 00, 00, 8B, 4C, 24, 2C, 6A, 00, 68, A8, FF, 40, 00, 8B, F8, 8D, 1C, 0F, 6A, 03, 55, 89, 5C, 24, 44, E8, 6E, 5E, 00, 00, 8D, 54, 24, 48, 52, 55, 89, 44, 24, 48, E8, AF, 5B, 00, 00, 83, C4, 30, 85, FF, 75, 0D, 55, E8...
 
[+]

Entropy:
7.9754  (probably packed)

Code size:
53.5 KB (54,784 bytes)

Remove 2ddfa00cf7d066d9e34fe01da6118546d1a941a0 - Powered by Reason Core Security