202006611_setup.exe

aTube Catcher

DsNET Corp.

The application 202006611_setup.exe by DsNET has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This version of the installer will bundle the Ask.com Toolbar, a potentially unwanted web browser extension. The file has been seen being downloaded from download1894.mediafire.com and multiple other hosts.
Publisher:
DsNET Corp  (signed by DsNET Corp.)

Product:
aTube Catcher

Version:
2.9.1390

MD5:
87e86bb05ce79a80611e3693b66276c0

SHA-1:
030f516a4083937adcd24b045cec94f89efead3c

SHA-256:
956bf97e4129d5fb592fcdc47c52dec22e4bd01497c223e3df6dd164bdabf618

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
Bundles that Ask.com toolbar as a third-party offer, a web browser extension that may modify a user's search and home pages.

Analysis date:
11/23/2024 3:01:57 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
TrojWare.Win32.Agent.ASSP
17445

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant)
7.9252

McAfee
Artemis!87E86BB05CE7
5600.7273

Reason Heuristics
PUP.DsNET.aTube.Installer.Meta (M)
16.6.9.12

Rising Antivirus
PE:Trojan.VBInject!1.6546
23.00.65.131220

File size:
11.1 MB (11,633,320 bytes)

Product version:
2.9.1390

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\202006611_setup.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/7/2011 9:00:00 PM

Valid to:
3/7/2014 8:59:59 PM

Subject:
CN=DsNET Corp., O=DsNET Corp., STREET=Plan de Ayala M3 L30, STREET=Mexico Revolucionario, L=Ecatepec, S=Mexico, PostalCode=55266, C=MX

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
009934C0F374A7790598E44428C2B46363

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:7RzB8qd5nNYmq9O2c87MvKA0FWLFjNUf6K2NMkTpsonqpVbACSA0XJyPlSCF+Q:9zB8qd5m9Is7/XkLgilMpVcvAbP9

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file 202006611_setup.exe has been seen being distributed by the following 35 URLs.

http://download1894.mediafire.com/cnlur81q0apg/.../Atube catcher.exe

https://dw.uptodown.com/dwn/8oycMxa82wSeRHz2xbpm5d8oH8wL1BmKYI5OZsOxZYaD3AVlZVTT9Jrf22AGe_JiFgx1NJMIdXq0HQ8_71NzDP8bxXgoBFZUkXUyXkfesH4ogX8aJ6HGJcCrerBIMLYi/oE15-fkUamp2Hnij-zdvI2HpHiVraQM5-gaXc7aOoNmSDn5ba1_WkcOrmZRnpnF0MWinMbfta7h7U8NsDSwAgfCtVCucMC2eTSd7pt6O8Md5D9r8hOlkzM32DVbAFSSO/3-0BfZj8VZHxTyUNdjvykpuTMILLoXkdlifimbyPXEsfYLPPO0dohR1gsCdfPqHgpYAd_zICffUNGBj2FiFzpuV2BUh3TLGUcSu8k9x5TA4JOx7Ml_1RYvLHQpOnH9Cw/.../

https://dw1.uptodown.com/dwn/92fuCwYaVx6PG46d-tsg4XtwylJf5T33iN3OJZIlUy6GCz5PQ0oepNpaeKQylNg8Qrii-7s3G9tC6r0LfFiYbfJMkZOWfn58bPekqoaP2RTk_Twr4ft34hBBvVnypIy4/d9uNb_Onc67Vvsm3Jwh174ibt8ymG3rTXwTMT1FwFKH-aueM_GbkLYg9VS967GhkhHXwN9nVx5o5_29us-3OYpu_63dQKh9p7cTJ_WLIk3ah0OA3mgJOIur_sgwA2rB5/FKFVzQp9BbvRyJHEMLgTwwcL1LREHeOZs5Wju7MikrDWPyzCbKK4XBYDRTe0lRUT6Fj75u9AoZHPpKMeF44iluVJAlgT9b34tToiuCuvfNr7XTlohAhZOI4Fi5eGBogs/.../atube-catcher-3-8-1390-es-en-br-fr-de-it-cz-cat-win.exe

http://dw.uptodown.com/dl/1448572234/.../atube-catcher-3-8-1390-es-en-br-fr-de-it-cz-cat-win.exe

http://download1894.mediafire.com/j5bnit6iivsg/.../Atube catcher.exe

https://dw.uptodown.com/dwn/BO5lQ3So2HJKIGQBJ4sHyp2FOhOmB80hd1O8qM-Okvvej2JfprRU86dFj1RA2bMw1nTr5-h4vQT0RZLYoSMDeMgxWQhgEBLP_a606L7PUCsVEDpxN5CAV-lRRe8nys10/R0cuNmK6Y8Bg53IDAZCo_2cBh1u_20k5-arJ6nGF_-EZg1WGeCc-3m0ylf_LvygcpYye6NMWi-TaBNc4EZqvpnYlhMSXOEg_NyBh1d6Mp0gLNgxtahHfO9NjLxycbNGS/mxdixGXnKk5PDAkXXF_h6P0CKQwoAjnPdKk6uQY1swIjtyemrRcsC6P3GnUTrAf6ic-UIx1JOXOg17Q4y7Y6HqdHYTRXfNd-bH9GihI22Dswh0QrssnC1YsPs_Ldl_j4/.../

http://dc280.4shared.com/download/.../atube_catcher_38.exe

https://dw.uptodown.com/dwn/zTrL4001traNDcY2NrrIT6DM7JBMcIV-U_-R0h2dXYRhtVY0C6PuIprrKp9T-4eNnwYxBC4c_QKGH1d-XdK-kULuxfNOnpuZeDiuz1Cx6xuSD20QJlmJrtEiUvgKetco/lq73WESK6OyeWwIjjnA1m5-H6kLi1PLRNXI1FTgNzdh8KXVEiE90MvcQFZwRN5o-C8-TlT2AxfiMFOeg9W0HIO2pMoomImWYafzdmXNILJwlzPHOjyXDD18zj5eJ6z0q/VkPkQYFabT_-KTkIyxNUan_HFReGKT9SGDLgTpZDiz-q6rPfA35GXFmYMdDWNEcK_CUuVY1zoexHtWpCBkxxYJpu5qJAjP1-XAD38wSk0q63fHZCg4pRdcaZ7LnBA-7a/.../

https://dw.uptodown.com/dwn/UTYA7XPZ6fJSv2aFZM0n9lecIIeLDIUSu0mPdKrYKpCM1W6ccYXaj8WACGgG9c3uEazjKHOGmG8Z_Hsoc_Owy7qBkJjsg7qK_VE01-_lDytnLblnrcKkA5NyrmsrPEqC/lzq1pPaebq8BHGD8icuju1a37Ag7gVUVYkDqt255zc57ub5fCxwBgMJJJf7al3w0tYirij_xr5bEIa7JMCv4cUiJhtHS8LgIMe2YWLdNZYg3lZF7Xdng08QDv3pZiSTD/C73_MAkEFaZF4Kym8BPTrZkjbQfpCtxygsfySoKfFxVeuThEQBKE6Gm3C0aTKK7q5NNCCAc93FFLhTFATUbRsznwDxoRzX1IdzoMFFonv6QD66wMOyKp-iEIDGAMt4Gu/.../

https://dw.uptodown.com/dwn/kjATAJHNRSeqTli6D18DxoL5NxGbBW7FD0F_-fAzXdUURKgTfZYeN0fgzfdrmjQo4O3QIx9pwoyk8L4CZigPf9M8DGPQVnU4k0UPHVpEbGzFhf5InI5-igwR_95LUd7f/_EDysctgt1jr-OZ9WBpj2dHmS6xuoU6aAZwfwUXx7Y_oDWzsAQjpFZR9hXvcCX-0GrW8Y40ll2g1lLR0J9bYi7uGaTFIF1mmgJY2mGJnGOlTgGegOzPOH_LMPtr87WfZ/BkYQNWmzds5a4i1vDfnsHf_BTNfHAp4SEJkm6XvXWpvxfEkDQU7ViEvGgSoCKJkDTWW1qNkRRHFVprH7yZqWmCBnBckFeaWHdhG082VJlYSBSLAMb00_R9eAL4xUE-F0/.../

https://dw.uptodown.com/dwn/wNT-_raMTno-5_TLYvtwqVpR-fCYIj7GqDnjkkw0To5mTaCYXZQoect4PnYDS6SCs62VAE50h9qnK30pbK_bvdmapgcrQKauU8Dm_p0cF46dMWeA91m_5H14t2KauQjM/ENPdxYyIgpy6SoxX7z2_5_eSyp2pvsOGvJXQj_gljqwyCQshUkoXN2xmyXhAwh1QiODl5iEgwC9eRLMuWE7EsiZVcA6L7E6L8F7z061Yo3eWSBQdXpHMWkliVfjK8MQd/eAylMBMfC5a1v5JktcwK0sUM6ulVPYZcSoInBTf9pu7NSdcBsM73xh9FQzcaurMoiF7ubQ25kfjHOhqsluOl3iUnDFSs03maaJNLvXZCZ8mEnB1HHTc65Cx7hpXCi2Ll/.../

http://download1894.mediafire.com/z3e19j79it7g/.../Atube catcher.exe

https://dw.uptodown.com/dwn/FWRyYwOfP0v_Sjjzg18jPlq0RvIq-3D2U7a2OPvBsTL0yNenNlLdFvzT6oWuEjU8qrqRW0xKziVk_xEtLGWs7-vwPVC48AniE-DObyboPxhgiYb4Tt_JzpSVNO3FNiu0/UiKedofkpLaxUyQ2DRphV2qMQCeADFGIAHmLENGtU_YEbLJKyIIP7QK9k-qdX2lVLPxoRY9CiBZiWRwFSvDWk85kGA4Lg44jxBllpyeaiW1x7tf4C4gLMAUhlW3z5rrS/4wS_WW-60GSi2Gdy2jksVZwCpUfQ_-_KE9G2D_hWwY4B0jBSWjw3QC7YLEKntoR_AdcygTLGv9C7Jl2am69q84i6YZjjlNncEdclIZ6Anr6yBGTtBonR0ipn_ZGgspYq/.../

https://dw.uptodown.com/dwn/32H-1gF3P1_HWBiDkDRQs1tCeOZ2qMNhiTd3csrG_6tBL4oT8Z0SPQo0Av9lklyNtDphyml4ck3qyEEy38hlGzNkA2EGk9UgZ85-g30mXR1p65I8ZpxDC8zJy1r3T3Ez/Oq8UABXxCX9mo6MXoHkwO2SPEApJm7W3pewoCE9biWVFcajNAUxidEn4CJc0KqSe-LBmFQUqFEsU60n_O-zo3l1lhshgE1yiMVbr5IFbnO0AFvRgIZKzd41lW5Pdesog/hj4kWz0EDNlTtMTSjfpj41hzpfb9AX8V4XF9LYAEuzpZM1lYp1UoXAql3I3kMUgeS9s8c9OpEIAoBs77WXNLxVavPbocUGgGiFmWg1j58NZwJMe9EmJDqH0PJoIiZs5b/.../

Latest 30 of 35 download URLs

Remove 202006611_setup.exe - Powered by Reason Core Security