7zip-setup.exe

Download Admin

This is the Tightrope WebInstall which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application 7zip-setup.exe by Download Admin has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the Tightrope WebInstall installer. The file has been seen being downloaded from dc354.4shared.com and multiple other hosts.
Publisher:
Download Admin  (signed and verified)

MD5:
c61240a1f92ee621a99a4242e4c6f2d4

SHA-1:
122091740ba8ee1be508f732f2e1adf8c8043f28

SHA-256:
fa25db725b7d45e868b2d8f57d49ce40b24e0cc9c1a483bab6a102ea4d23ea57

Scanner detections:
6 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
11/25/2024 1:55:22 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen9
7.11.214.114

K7 AntiVirus
Unwanted-Program
13.200.15187

McAfee
Artemis!C61240A1F92E
5600.6730

Reason Heuristics
PUP.Tightrope.DownloadAdmin.Bundler (M)
15.6.19.7

Sophos
Download Admin
4.98

VIPRE Antivirus
DownloadAdmin
38182

File size:
4.1 MB (4,336,432 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tightrope WebInstall (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\7zip-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/3/2010 11:00:00 AM

Valid to:
5/30/2013 9:59:59 AM

Subject:
CN=Download Admin, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Download Admin, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
29529B0D185F8525A92A866D4A38DA3A

File PE Metadata
Compilation timestamp:
11/21/2008 7:28:21 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:oHRewf9jpbeej+h0eVo1kpNU30ABizKN9KGamkUb+p1SlGly6:oHRPfBj+WeakbQ0z49dWpkG

Entry address:
0x30E3

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 58, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, 23, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 90, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 4C, 91, 40, 00, 68, 60, E3, 42, 00, E8, DA, 27, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, C8, 27, 00, 00...
 
[+]

Entropy:
7.9546

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file 7zip-setup.exe has been seen being distributed by the following 3 URLs.

https://dc354.4shared.com/download/.../7zip-setup.exe

Remove 7zip-setup.exe - Powered by Reason Core Security