{122bd04d-90dd-4023-828c-37bba48c6be9}

The file {122bd04d-90dd-4023-828c-37bba48c6be9} has been detected as a potentially unwanted program by 17 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from download.softobase.com and multiple other hosts.
MD5:
c922c707b8414be1dd65ae459c3f4893

SHA-1:
8a9b80231b3cc9b0b470f091a940cd3853e73378

SHA-256:
4f4ba41d526f881bfd95a9d7e6d9fedb92e88fac66cfec91a77c217529b83570

Scanner detections:
17 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/23/2024 6:14:49 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downloader.Gen6
7.11.183.0

AVG
InstallCore
2015.0.3281

Bkav FE
W32.HfsAutoA
1.3.0.6185

Comodo Security
Application.Win32.ClickRun.A
19990

Dr.Web
Adware.InstallCore.68
9.0.1.0327

ESET NOD32
Win32/InstallCore.AF (variant)
8.10666

Fortinet FortiGate
W32/SPNR.0BIJ12!tr
11/23/2014

F-Prot
W32/InstallCore.V2.gen
v6.4.7.1.166

K7 AntiVirus
Unwanted-Program
13.185.13888

Malwarebytes
PUP.Optional.Wajam.A
v2014.11.23.01

McAfee
Artemis!C922C707B841
5600.6937

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.141121

Trend Micro House Call
TROJ_SPNR.0BIJ12
7.2.327

Trend Micro
TROJ_SPNR.0BIJ12
10.465.23

Vba32 AntiVirus
BScope.Malware-Cryptor.InstallCore.2691
3.12.26.3

VIPRE Antivirus
Click run software
34498

File size:
1 MB (1,072,912 bytes)

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:AbSdh/8YjWbmCEqLDcqwZEfmo4wLyXhYdH3lnPE:GSdh/83CCEO0RY5Fs

Entry address:
0xCACB0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 10, 2E, 41, 00, E8, 9D, DE, FF, FF, C3, E8, 9A, FF, FF, FF, 8B, 43, 0C, 01, 46, 04, 8B, DF, 3B, EB, 75, C2, 8B, D6, 8B, C5, E8, 55, FF, FF, FF, 84, C0, 75, 04, 33, C0, 89, 06, 5A, 5D, 5F, 5E, 5B, C3, 8D, 40, 00, 53, 56, 57, 55, 83, C4, F8, 8B, D8, 8B, FB, 8B, 32, 8B, 43, 08, 3B, F0, 72, 6C, 8B, CE, 03, 4A, 04, 8B, E8, 03, 6B, 0C, 3B, CD, 77, 5E, 3B, F0, 75, 1B, 8B, 42, 04, 01, 43, 08, 8B, 42, 04, 29, 43, 0C, 83, 7B, 0C, 00, 75, 44, 8B, C3, E8, 35, FF, FF, FF, EB, 3B, 8B, 0A, 8B...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
826 KB (845,824 bytes)

The file {122bd04d-90dd-4023-828c-37bba48c6be9} has been seen being distributed by the following 2 URLs.

Remove {122bd04d-90dd-4023-828c-37bba48c6be9} - Powered by Reason Core Security