1stbrowser.exe

Installer

SIEN SA

The application 1stbrowser.exe by SIEN SA has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from stapibrowser.getinstall.org. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
S  (signed by SIEN SA)

Product:
Installer

Version:
4.42.1.1

MD5:
6f11a3108727b1a6b0287be944e18c0b

SHA-1:
23d6cd189d3f35b0f238d267a32352cbdd16f9ef

SHA-256:
82eb7dc2de6c7c270aab6447fe4771e1841259280923e5b301f50fa55b6b81c3

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 2:44:07 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien (M)
17.3.16.9

File size:
2.4 MB (2,505,880 bytes)

Product version:
4.42.1.1

Copyright:
Copyright (C) 2016

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/6/2016 8:20:17 AM

Valid to:
6/7/2017 8:20:17 AM

Subject:
CN=SIEN SA, O=SIEN SA, L=Paris, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121854422706CE0F08C49817C88B651891F

File PE Metadata
Compilation timestamp:
10/10/2016 4:37:41 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x1501B0

Entry point:
E8, B0, 08, 00, 00, E9, 8E, FE, FF, FF, FF, 25, F4, 9A, 5B, 00, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, F2, C3, 8B, 4D, F0, 33, CD, F2, E8, 5C, F5, FF, FF, F2, E9, DA, FF, FF, FF, 8B, 4D, EC, 33, CD, F2, E8, 4B, F5, FF, FF, F2, E9, C9, FF, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, C8, EF, 61, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, F2, C3, 50, 64, FF, 35, 00...
 
[+]

Code size:
1.7 MB (1,798,656 bytes)

The file 1stbrowser.exe has been seen being distributed by the following URL.

http://stapibrowser.getinstall.org/1stBrowser/.../setup.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove 1stbrowser.exe - Powered by Reason Core Security