installer.exe

The executable installer.exe has been detected as malware by 5 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from jmp2offer.com and multiple other hosts.
MD5:
1c2b84ed540255d153c70c64bca48a8e

SHA-1:
b93f54e64ebb3b034303ec4a2e16a755acdbde89

SHA-256:
1c41084ee3f265267708757a27b24ab446cb3c5acc996c99453773026dcb0ed3

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
9/8/2026 11:32:22 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.7400

Panda Antivirus
Generic Malware
15.12.29.06

Qihoo 360 Security
QVM08.0.Malware.Gen
1.0.0.1077

Reason Heuristics
(M)
16.6.5.15

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48 [F]
23.00.65.151227

File size:
332 KB (339,968 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\installer.exe

File PE Metadata
Compilation timestamp:
12/29/2015 3:48:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:iQonFXoGiTJGJQ26jm4hrlexxFS5oJAgqn1hOQVTkRX:ZonptO2vWqxY5/gWIQVo9

Entry address:
0x47F04

Entry point:
6A, 60, 68, 60, F1, 44, 00, E8, 30, 15, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 84, 16, 00, 00, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 30, F0, 44, 00, 8B, 4E, 10, 89, 0D, 38, 1C, 45, 00, 8B, 46, 04, A3, 44, 1C, 45, 00, 8B, 56, 08, 89, 15, 48, 1C, 45, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 3C, 1C, 45, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 3C, 1C, 45, 00, C1, E0, 08, 03, C2, A3, 40, 1C, 45, 00, 33, F6, 56, 8B, 3D, 24, F0, 44, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
312 KB (319,488 bytes)

The file installer.exe has been seen being distributed by the following 2 URLs.

Remove installer.exe - Powered by Reason Core Security