bitzipper2015setup.exe

Baromaroro

The application bitzipper2015setup.exe, “Baromaroro Setup ” has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Product:
Baromaroro

Description:
Baromaroro Setup

MD5:
d2c54d6f89253ee5d3f02480191f5a82

SHA-1:
62a939ee5f98dc7a0f60786601e1b81b07806644

SHA-256:
5d848bea185f57c2d656c6adce1fce1b79913cf22512a23bc7ea7c2cee8f30c2

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/28/2024 12:51:48 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.RE11 (M)
16.5.16.18

File size:
1 MB (1,052,999 bytes)

Product version:
2.5.8

Copyright:
Fast Wizard Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\bitzipper2015setup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:RHsXdMZjAomR9Ev5OusSFoaa9x1rk8+rzEv++0uacyC:RMtMZjAlHEvOSFodNrP+rZ+gG

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9187

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file bitzipper2015setup.exe has been seen being distributed by the following 50 URLs.

http://www.apptownnow.com/WVl6OTRQV040UVRobFRYUTRRM3BOTTFaTGNVOWxRMUpHUld3eVExZDFZV0VsTWtack9VeHRTWGRwVGxBeVdHTmxSU1V6UkNaalBVUnhiSGxxU1VwSVQxTnNabTR5TXpWMU1FOXpjSE0yWWs4bE1rWXdhazh6VTJNMGFEZEdRVUpvVld0MGVrOVhhMDVxTUhaTFowY3hjRmRxYTNGTWJsbExTQ1V5Um1zM1ozUlRWVWhtYkdrMmVUVmxhRlJZV1dwNWNHRkRUVWR0WkV0V04zZGhRWFF3Tm5CREpUSkdURVZQYzFGd2J6RkViRFl6Y1hKcWRsZHBhR0pqVXpGWllVSjBOMDFDVHpaTk0wNVpjRTVDZW1RMldFZ2xNa1puSlRORUpUTkVKbVU5TUNaa2IzZHViRzloWkVGelBVSnBkRnBwY0hCbGNqSXdNVFZUWlhSMWNDNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1ozZDNjdVltbDBlbWx3Y0dWeUxtTnZiU1V5Um1SdmQyNXNiMkZrY3lVeVJtNWxkMlZ6ZEM1bGVHVT0=

http://www.bitspackagelaboratory.com/c?x=NHSBPORBtJSFmSvQ0/t3W8nr1R2Ji7dCh8yPZcRpJKg=&c=wCXaRuICbW aLU48rGPuM zSAQPXxZNmyLzJq/TfGrOyqYdK7G1ZEUn5Qs2a/TvTf6NJFSN/twCuNecQ0F97zogUv9VfRuIl/jfHTQgCdh1nmtS8EYXKLJP7LWdNBVyDubnNUZVEHsL/lFGfU6MPrY5Ir7DewaD PhWn2DsA L6LG7YOMAP1JkXw9rWb69CR&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.applicationflashpresent.com/c?x=289gj NMQEbYZBCTCa EjlGkpp5PZ/C68ckiSfZkL0g=&c=8zaVlxl9vQas6unmjkdma2Rs0njLBYCWYX1uaVQjzspQ95qPgtsGpSKQIvGkyj7vgctciCaZNREYnAlyMtBKouk5cQ15H cyI1XjbETFW7 cY/5I3NmisywmmiGyQNRzOBslvCD9diHb GmaxIuonFPoM8K5DJd7Kg7LtURruQWGF3 oOaRZtT8C64zTvuz5&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.bulktodaypresent.com/c?x=hnuSSe4k8iXrZQCA5umILnYYSC5ZXNsQ1C0V0DQmxts=&c=vk DlPMly/UZGW966FVF9xKOfW/kqNbF6KlSb3ccykxwdDCRiNtHCBWEygPXPH iRuL7vkQmB8m9JvwOjjP hb52Lvq2iG2tvIV676 91 X5waRc0yGPET2chjRhTkcGE8MHrTq3FcS/VLqX3LpqzPHWT3J3I9qGHccUXc5rS5jXlFToXKa F5vaoxLNnHdT&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.appsapplicationshare.com/c?x=rnBYfmP2OTzjVMI7Hzhj9buXeJgn/mnBJj/EbpiJRTk=&c=XDWtiZpgJzkYzfWGPViKf4aUTY2cbOrHTHDKEgjWKFBdCacE7G9YrhfCVVSH9uzb55hK4YtPg3n3YbzZimdrr0Li/j5R5KhG5tHrlB49JPEXkX7bxIUsk02linLNhTH9BRXqH42gA9A1JM3SfFZoHZ0RHR3EWQcRq6RPTWhW NjykAY8xvtI P6dz7ToWXbn&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.appsapplicationshare.com/WVl6OTRQWFpHVEdFNWRtbDROVlZUUm01MU4xWkxaRUZUVUU4emJHMWhOWFZRZW1aNWVuTTNWRmt6UmpGS2JXc2xNMFFtWXowelNFTkliVUpTYWxCTFJFSkRiaVV5UmxoU1dXSkxOemQzTTBNd2MzSmhNME5DY0ZCWGIwbHNiM1ZPTmpZeGNsZHdOMVJsUlhaWGRHdHZhekZCUlVoa05HSlhZVWxhV1c1T09FSkpaMmhTUWpOUk5tbHJTamh6ZUVsYVZEaDJXREJNV0VkTmJuQmthVEpOVldGVE1HMDNaWGxEUTJaTlpHbFRXbFpXUTJ0clRWazRTbWhHTjNoRVIyZE1Ta00wZUZWWmR6SkZhVWRWUVNVelJDVXpSQ1psUFRBbVpHOTNibXh2WVdSQmN6MUNhWFJhYVhCd1pYSXlNREUxVTJWMGRYQXVaWGhsSm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROQkpUSkdKVEpHZDNkM0xtSnBkSHBwY0hCbGNpNWpiMjBsTWtaa2IzZHViRzloWkhNbE1rWnVaWGRsYzNRdVpYaGw=

http://www.currentappdownloads.com/c?x=oXIcC98ZPB S/SprM8I87c4MaSSlLpWwZVAcwRCy/LI=&c=LXJ6GY3uNPt4WCEpkT1/V8jgqtS7sytjdYYrIoXuuxloufDdDY1Fi7x0/Q01YQBVDlyYoNrfGg9dlxSrbRNn5uAX1oS7sstNxDhIRSH5bykf4yOqx3aSaABgU/AkaojJ85hdF4GH2U1kcj7DPqM5ZIDGnc1yuvHZuPr9QE N76Jgcifk8IrlTmXszMZzFkQe&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.bitspackagelaboratory.com/c?x=GTSugdvkLKVF9v2WoCXnaNLNarb6AAkW37xO8IYi8p8=&c=b/yWNpqwMU0m3fj9C6PRLPRE/uoUqt5vc2F7ASKJy80GHofd6k5zcvxR5UKTvKfmC1MaG29j4eTiqLmBTtqE0aziwewP7eYZv4dF303uij/2SisuyEFTvWgpnPmFiZETPEF7tVEG1ar/b NK/XbhKpULN vU0yfTrRIN4v8rSdzQR3lmk/XRNRqqoSeGIe4d&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.apptownnow.com/c?x=lHFDUdo/tIpde7rr9fi68CLOqhOGAbCoquq5tT6acTs=&c=mswajYkGZg4nqzqAQku5oHKwI1AtbLVhOQS1 7YomXehjo7uSYvE20SrVHzd7AUhAlL518KNI6LXX3/ds41O5iEiud3D0uuw0HJWgSW4 CBxlAo6EQRsgTKwvguLFFJ0B2bvnTURR/UA2w0nGjek8Qt4fKG6mxbeZbTfsNdUmrMhM8BB6QkkgbgC77iqAK7d&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.bulktodaypresent.com/WVl6OTRQV0pLU0dsdmJWQjFkWEJWZDI1eU4yUk9NbFJIVEhoWFFXZFFWRW80VFRGS1YwcDZTalphYkRGbVRFVWxNMFFtWXoxVlNsWkpNRmc0ZUdWWEpUSkNTVGx1TW0xT1JtNW1hbGhSVUdSbVN6ZFdUWGMzTkVwTVUwUmtRMGhqYlU1U2MyeHBVSFp2YlZreE9XRnRObFkwYW5WNFNtVlpWbEpxVUNVeVJtZFRaSE0wUjB0RFkydEJhbEJFY1RCc2JWZHVkMmR6ZG5nbE1rWkZWR3RhV1hBeFpUQjZTMVVsTWtJM1drMDBTa3hVTVRsTmVEQkZaV3hRZFVWbE9HWk1abXg0WmsxaU1qTlhXVWxQWkZSS1psb3hVU1V6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxQ2FYUmFhWEJ3WlhJeU1ERTFVMlYwZFhBdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdkM2QzTG1KcGRIcHBjSEJsY2k1amIyMGxNa1prYjNkdWJHOWhaSE1sTWtadVpYZGxjM1F1WlhobA==

http://www.bestsharehead.com/WVl6OTRQWGRtUWpKTldqZG5aRTVWTnpSWFdGWWxNa1pvWVRoVVIwZG9jamwzV2poTVVqbHljWGRRZUhGNlowMUdOQ1V6UkNaalBWbDZPRlUwU2twcFlrVjFPVEpUYzJoVE5YWTJjVVZ5VWpGUlMxRmxNSGxVUmxock1XNXVKVEpDY0VsSmFrTkpOa3QwVWxoa1JISlpkMDFLTmtaS1FVTTFhbFJCWms1RFpGTlhUVEJ2VkRGSlpWbDRWbEZxTjBwd1pXVnRlazFyYzNGWlRuQmpUbVZ0Y210VVowZE1iemhvVkhnMVZWbFhjVGczYkhObWMwaHplbWRLWkNVeVJtcFFSbGRTYVhOQk1EZHBiVkZqY1dSUFQxRWxNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05UW1sMFdtbHdjR1Z5TWpBeE5WTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuZDNkeTVpYVhSNmFYQndaWEl1WTI5dEpUSkdaRzkzYm14dllXUnpKVEpHYm1WM1pYTjBMbVY0WlE9PQ==

http://www.ranchtourhosting.com/WVl6OTRQVVYxUm1sMWRWVkNhekZHVVhBelNrTlJORTVVT1RFMGVTVXlSbElsTWtKNVJ6UnNNRVZLVEhaMFlUWmhjVkJCSlRORUptTTlZME00VDFNbE1rSldUMHBoUldwdWFrVldWRGR4Vmxkck9FTmlkRTFGVDJadWVVSmFkalIyUkZobmRpVXlSblZMY1VGemJXZG9TRmh3TmtzelpHaGFKVEpDU0V0RlkyWWxNa0p3WWxBME5WaHBUR1pLWTJwSWNsUjVWazVhVnlVeVFsazBhVkJYUVhKUWN6ZHdlVU40VEVOS0pUSkNWR3hQUkVJM2NuZ2xNa1pYUlhWWlZDVXlSblp2VEVOTkpUSkdjVlZLY1V0SGNYUnpPR0kwSlRKR1RsQkZiWGhzZEU1S09HY2xNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05UW1sMFdtbHdjR1Z5TWpBeE5WTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuZDNkeTVpYVhSNmFYQndaWEl1WTI5dEpUSkdaRzkzYm14dllXUnpKVEpHYm1WM1pYTjBMbVY0WlE9PQ==

http://www.dlpresenttours.com/c?x=i4JHTrHeECeyG4Iqi 0MxGDmT9UIDhQ96i3/EyNw4Tg=&c=pls/CP5ADFFNxR1M1tI5G NXNAXGK837mbRHqFA1BV00twyB/4E9RCWUnf25U6TWLX8brmaY55G6w5nOxbvvkY8ywMP2uYUy0dme7B0vFSdjvP9s7Wq58akqTmm1ytjCV/ZHEp4huArLTZqCTqBLFfdBJ9Ep1yjZP7y5Hlc8eYEbC7j0ZAkQOravHQEziYNR&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

Latest 30 of 90 download URLs

Remove bitzipper2015setup.exe - Powered by Reason Core Security