1a66a9274878d83c5c566b0bbf4846c9d59d1da6baf03401ff3d7abe24f925c5.exe

Instalador

Unilogic Informática Ltda. - ME

This is part of the Installmatic installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application 1a66a9274878d83c5c566b0bbf4846c9d59d1da6baf03401ff3d7abe24f925c5.exe, “Instalador Setup ” by Unilogic Informáticaa. - ME has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Installmatic Setup installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from ca.offers.multiinstall.com.br and multiple other hosts.
Publisher:
Unilogic Informática Ltda. - ME  (signed and verified)

Product:
Instalador

Description:
Instalador Setup

MD5:
a4c63ae17d2c7ed4c034a6d6274cf320

SHA-1:
6adba136b152276ba6382af98da70358cf567d99

SHA-256:
277d840cda50381be0f97a604ac2e196d6bdf0c1cf5d9aadb6b05e50fd07d55f

Scanner detections:
12 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
11/27/2024 10:56:31 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Zapp.A
959

avast!
Downloader-TQT [PUP]
140617-1

AVG
Generic
2015.0.3437

Bitdefender
Adware.Zapp.A
1.0.20.860

Dr.Web
Threat.Undefined
9.0.1.05190

Emsisoft Anti-Malware
Adware.Zapp
8.14.06.21.10

F-Secure
Adware.Zapp.A
11.2014-21-06_7

G Data
Adware.Zapp
14.6.24

IKARUS anti.virus
PUA.MultiInstaller
t3scan.1.6.1.0

Kaspersky
not-a-virus:RiskTool.Win32.Agent
15.0.0.463

nProtect
Adware.Zapp.A
14.06.20.01

Reason Heuristics
PUP.Installer.UnilogicInformaticaaME.
14.8.7.21

File size:
3.8 MB (3,999,016 bytes)

Product version:
1.0

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Installmatic Setup (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\1a66a9274878d83c5c566b0bbf4846c9d59d1da6baf03401ff3d7abe24f925c5.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/22/2014 10:00:00 PM

Valid to:
1/23/2016 9:59:59 PM

Subject:
CN=Unilogic Informática Ltda. - ME, O=Unilogic Informática Ltda. - ME, STREET="Rua Formosa, 79 - CJ 83", L=São Bernardo do Campo, S=SP, PostalCode=09626-060, C=BR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A118F4B63F570A676E2C3CB48638E2E4

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:s9U3nMM5LUUYqU8elGs/waqWtV3unKisKBmHq0YijytbHQomnCVPjxmQ8DaCXLPb:mU8AnqlGLWVWVCZYiW5HWSPv83Xrxr9T

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file 1a66a9274878d83c5c566b0bbf4846c9d59d1da6baf03401ff3d7abe24f925c5.exe has been seen being distributed by the following 9 URLs.

http://ca.offers.multiinstall.com.br/b31ca166d53f2593fbc08bba7d3ec344d59d1da6baf03401ff3d7abe24f925c5.exe

http://ca.offers.multiinstall.com.br/ae523f64f5599816a1c1eeffbf9079e0d59d1da6baf03401ff3d7abe24f925c5.exe

http://ca.offers.multiinstall.com.br/ae181eaf8587fffcb90f3eb92a7bf3ffd59d1da6baf03401ff3d7abe24f925c5.exe

http://ca.offers.multiinstall.com.br/f3fe6ff1dbf583e21b50e26e2fb853b9d59d1da6baf03401ff3d7abe24f925c5.exe

http://ca.offers.multiinstall.com.br/a771c08301df9b4ab860b91a9819ba1ad59d1da6baf03401ff3d7abe24f925c5.exe

http://ca.offers.multiinstall.com.br/6affa13b5cb510aad38f5030a1b8dd32d59d1da6baf03401ff3d7abe24f925c5.exe