bitzipper2015setup.exe

Sak

Locat

The application bitzipper2015setup.exe, “Sak Setup ” has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Locat

Product:
Sak

Description:
Sak Setup

MD5:
37cf196c25241d9feaa1249872a00598

SHA-1:
b854b73e15bab456e997e54840fa1168772941a6

SHA-256:
ba65858e3b8a41a835a357ca0231569579e06e98bf5f6ec89f1dd29cfe0eabe0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/15/2024 3:34:43 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.11 (M)
16.3.6.13

File size:
1.1 MB (1,164,316 bytes)

Product version:
3.2.2

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\bitzipper2015setup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:VCzSuQK2mOouEq50eNKMp7hkats2COTy7WlhJ0FzGjdD5wc8oyQTd4XT4j1jl0w2:VCzMK2mOo0TgAkaS2vnl7Sz0dFwrb843

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8696

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file bitzipper2015setup.exe has been seen being distributed by the following 50 URLs.

http://www.towersoftwarebundle.com/c?x=ZJtuuXwQjOiLCqhbWFeU8KNimPk85JGXsmsrZcLA2uo=&c=BSl5mxj/teeuc6S2gXGSjIFRrKZtHjU1MolAB0ctiTgn4k7/fioqG/wfbe77uPwcHyeGP9Qv65WBY4pkmpRKFgY6HyHOVA4/PI2dMRx3berBHeBpP8WdeX7MBPk F86d2zV7Mz3c9VA7N7vfYb0myuSJFNjLD8G9uqVHpI02wI/lOAbACZ V flhMpmh23CW&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.presentfilestag.com/WVl6OTRQV0ZCTmxReFVHTjZla1JTY1dobVZYUlhObWg0VEdWaE5WRnJWMHh6ZHlVeVJqSk9KVEpHTjFSdVMweHFTMmd3SlRORUptTTlUbVl4WTI5dFYyVTFNMWRKUVdsNkpUSkNNRFpDUkhRM2VVSndXbXN5UWpSYVIxTm9VVFphTkVKd2JrZGhSR0pHVDJSTVptbHdRMDR3YUhFNWEzWkJja2dsTWtKb2RFMVJkMEZvZGtkWlEzWldNVGxQU25oV1ZpVXlRbXhwYlRCbE4wUmpiR2RsVERjeVJucFdlaVV5Um1sSmNHVnBSVXRxWm5SWFJHZDVRMUF5TVRsVlJGRjFiQ1prYjNkdWJHOWhaRUZ6UFVKcGRGcHBjSEJsY2pJd01UVlRaWFIxY0M1bGVHVW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMEVsTWtZbE1rWjNkM2N1WW1sMGVtbHdjR1Z5TG1OdmJTVXlSbVJ2ZDI1c2IyRmtjeVV5Um01bGQyVnpkQzVsZUdVPQ==

http://www.clearpackagedownload.com/c?x=mqEYXXe0nNwZPk/xXPhmJDBwuYopklIfZYzlgQxWb2U=&c=CWPPWfZmdYAG2jSWlzV0IMOlHrVO4pLPnUKAVl9QyqdGGHjlxdfEYTsJXU0aUpO59zq O4 xG/u5WoriGMM2/KWgfnLCqC45Amrniy83BCwv6DvIqCUnqynP5eGTug V2p1no3dPFGbvCV7nbuDmS6aEObhJgk2GReUVIgS/ocNSeEm8lYf2vhoRMZwWBx3&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.binariesfarmsend.com/c?x=4y9HAbb1B9dQ51wiO1AbB9IH4LgLk8snZPdDTMJv/A8=&c=L3Pw6kOT1x/lnETJOFsXfadRHOcSYlXz8NLt1KQXPb0lkoc/jG6sn8y6ofoEaloXwROWfBZDoPpXefEWfdQIpVh3sKA/FB83BT1KfTCOeqaxPAVmeJVgZYUuZt3Ec1P3U3nT4hYhnucZWjSa7NhRE7IPn41ensiOgf4EzNas2Nn fEoIA3Lt4EzjfIbol7YZ&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.binariesfarmsend.com/c?x=MQ225Gj4VnqbW36bRsUe1a5CTJuByig6YBWmk5HAwdQ=&c=TKl68b9gj758nRTiDtH3gK33Ir8FfvMc8e0h gUN9tTxD33PGbkmobd0/APl4jQiG4/ZhT5emsn2ukFVWBPYE6MALkg7wWodDYgB0Up2on/xETDiBugIEbz01BfBvYSknq6aptjWcNR IRQiCBsvCHkGHYookHRIRBu3Ft0uIPkWX6gePX4xX09Kxs0PijHl&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.vaultappsranch.com/WVl6OTRQWFZZZWtNd1dIZHlXa3RNWWtOWFVtcGFhamhLZUZaM1VHdGFlVzUxVkc1TE1XdDBaMmN3YVRNMVprVWxNMFFtWXoxTmJYcFhNekZUU0dSTmNFUmFiVTl2ZEVKTk9FWXpRbVIwZW01UllrUnNaV2hpTkhGU09UWTFURnBaYWt0d00za3hURlZtUWpnM1RDVXlSbGhMUVRKSGVYZHBWRlJYYkdkSE1TVXlRbHBEVWtwQmNrRkhiMEpUTWpaaFVteFRXSFEzYVdjNGNtNTJlR1Y2U0ZsSFpsbEJVMVp5YzNNelVtZHpZM2hQWlZSQkpUSkNaVUZMYlU1MVVtNWhVWFJPWjJjeFIwcE5UazFyVm1aclFYY2xNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05UW1sMFdtbHdjR1Z5TWpBeE5WTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuZDNkeTVpYVhSNmFYQndaWEl1WTI5dEpUSkdaRzkzYm14dllXUnpKVEpHYm1WM1pYTjBMbVY0WlE9PQ==

http://www.giftbinariestowers.com/WVl6OTRQVmRtYjFKemRrbG9TakY1TmlVeVFrOTVVbUpDTlhwWE9FaG5iWEJYTWxONlZsVnRTV05XU0ZZbE1rSTRNbFJySlRORUptTTlObEpLYnpKVlpEUTNNRkV6V0hFMVJXeEpSWGxIZDFwWk9IbHZkRmxMYVVWSWMxTktkR1JvZDFOcWRqRjNPV1J2YUNVeVFrUm1lbUpXU2pVMU1IWlRNVVpUY3pCaVpUTlFNVUZXVWlVeVFrTnJjbW8zT0Roc016RTBTVkYxTmxoeFMySlNkMVlsTWtadWRESnRKVEpDZVRGRWQwbHdUbkpUY1ZGMVZpVXlRalptT1hRMFVHZG5kbkZwTWtKMFpUUllTMlJXVlRobWQwTWxNa0ptUlZNbE1rWlZiVkVsTTBRbE0wUW1aVDB3Sm1SdmQyNXNiMkZrUVhNOVFtbDBXbWx3Y0dWeU1qQXhOVk5sZEhWd0xtVjRaU1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6UVNVeVJpVXlSbmQzZHk1aWFYUjZhWEJ3WlhJdVkyOXRKVEpHWkc5M2JteHZZV1J6SlRKR2JtVjNaWE4wTG1WNFpRPT0=

Latest 30 of 78 download URLs

Remove bitzipper2015setup.exe - Powered by Reason Core Security