1stbrowser.exe

Installer

SIEN SA

The application 1stbrowser.exe by SIEN SA has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from bit.ly. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
S  (signed by SIEN SA)

Product:
Installer

Version:
4.21.4.1

MD5:
b7e37814eeb78291aed51f8e78ef1618

SHA-1:
b425c527a0cedfa3192c12c95f620f63a0174781

SHA-256:
16094ed4b193706daa2e1cb23ca672129c8cf74e65077563d17d7dcc3d948354

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/24/2024 12:51:34 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien (M)
16.8.3.20

File size:
2.1 MB (2,211,432 bytes)

Product version:
4.21.4.1

Copyright:
Copyright (C) 2016

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\1stbrowser.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/14/2015 9:05:56 AM

Valid to:
9/14/2016 9:05:56 AM

Subject:
CN=SIEN SA, O=SIEN SA, L=Paris, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11213DB3C4AD369B17F720086E1BBB7BB700

File PE Metadata
Compilation timestamp:
5/19/2016 10:05:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
49152:iTVpfC01iCaPUUlCAaLXLWUG6R6Gdc7B0i5as9ttmnxlRHO4/5XkSaK/F0oYOdK6:iTVpK013QUgCFXLzG6RG35X5mnxlRHOU

Entry address:
0x1320E4

Entry point:
E8, 6F, 08, 00, 00, E9, 80, FE, FF, FF, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, F2, C3, 8B, 4D, F0, 33, CD, F2, E8, 5A, F5, FF, FF, F2, E9, DA, FF, FF, FF, 8B, 4D, EC, 33, CD, F2, E8, 49, F5, FF, FF, F2, E9, C9, FF, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 14, 21, 5F, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, F2, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24...
 
[+]

Code size:
1.6 MB (1,635,840 bytes)

The file 1stbrowser.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove 1stbrowser.exe - Powered by Reason Core Security