1stbrowser.exe

Installer

SIEN SA

The application 1stbrowser.exe by SIEN SA has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from www.softonic.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
S.I.E.N  (signed by SIEN SA)

Product:
Installer

Version:
4.7.2.14

MD5:
f53b8d171af9360a1987156788ab60d3

SHA-1:
568e4c040ba342278c5fa5c9f364568ba485e139

SHA-256:
5666cd863dbcab9e75a2fd8e38a287b348ae712777d039fa54e9ff4ca0af0671

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/12/2025 9:26:43 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien (M)
16.8.5.16

File size:
2.4 MB (2,507,880 bytes)

Product version:
4.7.2.14

Copyright:
Copyright (C) 2015

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\1stbrowser.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/14/2015 8:05:56 AM

Valid to:
9/14/2016 8:05:56 AM

Subject:
CN=SIEN SA, O=SIEN SA, L=Paris, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11213DB3C4AD369B17F720086E1BBB7BB700

File PE Metadata
Compilation timestamp:
2/9/2016 8:23:25 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:LThut8MbTgCkmLrLEuHkgIq6boIWnM8fHyPqsFdqagaOsWJsa9O6vES6Xg6:Xwt8MbTjkm7EuHkbq68FHyPqsCagaOsF

Entry address:
0x1354F3

Entry point:
E8, 44, 7B, 01, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 56, 57, 6A, 08, 59, BE, 74, 0C, 5C, 00, 8D, 7D, E0, F3, A5, 8B, 75, 0C, 8B, 7D, 08, 85, F6, 74, 13, F6, 06, 10, 74, 0E, 8B, 0F, 83, E9, 04, 51, 8B, 01, 8B, 70, 18, FF, 50, 20, 89, 7D, F8, 89, 75, FC, 85, F6, 74, 0C, F6, 06, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, C4, 52, 59, 00, 5F, 5E, 8B, E5, 5D, C2, 08, 00, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51...
 
[+]

Entropy:
6.3727

Code size:
1.6 MB (1,653,248 bytes)

The file 1stbrowser.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove 1stbrowser.exe - Powered by Reason Core Security