3gatomp3_setup.exe

3gatomp3_setup

TRUE SIGN (Rspark LLC)

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application 3gatomp3_setup.exe, “3gatomp3_setup Setup ” by TRUE SIGN (Rspark) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
Safe Download-3gatomp3_setup   (signed by TRUE SIGN (Rspark LLC))

Product:
3gatomp3_setup

Description:
3gatomp3_setup Setup

MD5:
fd92dae62630b5ccd1f0501d221826af

SHA-1:
978b61f22144e610770ee9e3c8eeb95d3ae980cc

SHA-256:
21cff9adc0033b96ec7fca408ae13f602cdd3c881082f3b16159ad08272e8a1b

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/28/2024 2:40:12 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OutBrowse (M)
16.11.27.19

File size:
413.9 KB (423,832 bytes)

Product version:
1.0

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\3gatomp3_setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/3/2015 9:00:00 PM

Valid to:
5/3/2016 8:59:59 PM

Subject:
CN=TRUE SIGN (Rspark LLC), OU=SOFTWARE 360, O=TRUE SIGN (Rspark LLC), STREET=2929 1st Avenue, STREET=405, L=Seattle, S=Washington, PostalCode=98121, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008A16B47C9934711828FBD33998107D1A

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:P/QiQPJGOpJZVpdtyhpaBLQ85frl2LMK/q1HgSBg3xJ0X5MpLX2d24L5zUeA:nQiGJGObZVpXyWjXIMH1mhJ0pMOp6l

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file 3gatomp3_setup.exe has been seen being distributed by the following URL.

http://software-files-a.cnet.com/s/software/14/27/68/.../3gatomp3_setup.exe

Remove 3gatomp3_setup.exe - Powered by Reason Core Security