chrome_setup.exe

Generic Software

PlatformMax (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application chrome_setup.exe, “Generic Software Setup ” by PlatformMax (Fried Cookie) has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The installer is marketed through download protals and search ads as Google's Chrome web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Software   (signed by PlatformMax (Fried Cookie Ltd))

Product:
Generic Software

Description:
Generic Software Setup

Version:
2.2.3.1

MD5:
09a97ae23b155d17d3d5103ce6b13e8f

SHA-1:
e24812010d8553862e85ea6461175c3ce5e3dfa1

SHA-256:
9019a92f0e9d860fb794927e6415cb81bcff8480386532467e56e17cd160fbff

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/25/2024 5:06:59 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Dropper-gen [Drp]
2014.9-150617

AVG
Generic
2016.0.3075

Comodo Security
Application.Win32.InstallCore.DXC
22483

Dr.Web
Trojan.InstallCore.890
9.0.1.05190

ESET NOD32
Win32/InstallCore.ZX potentially unwanted application
7.0.302.0

G Data
Win32.Application.InstallCore.EG
15.6.25

K7 AntiVirus
Adware
13.205.16276

Malwarebytes
v2015.06.17.05

Reason Heuristics
PUP.Installer.InstallCore.Installer
15.6.17.12

VIPRE Antivirus
Threat.4150696
40830

File size:
675.5 KB (691,696 bytes)

Product version:
2.8.0

Copyright:
Application software

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\chrome_setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/27/2015 10:22:51 PM

Valid to:
4/27/2016 10:22:51 PM

Subject:
CN=PlatformMax (Fried Cookie Ltd), O=PlatformMax (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11219ED90C889457EDC655A4858AD805D448

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:znLGiEwyuLH3g2SVEs/or+cofQNtvzYY+J1UVhG61bVxZBBJS3:znLv7hw2StAho0z9+JiV1xFE3

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.8886

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to static.25.179.251.148.clients.your-server.de  (148.251.179.25:80)

TCP (HTTP):
Connects to static.176.61.76.144.clients.your-server.de  (144.76.61.176:80)

TCP (HTTP):
Connects to ec2-54-243-96-231.compute-1.amazonaws.com  (54.243.96.231:80)

TCP (HTTP):
Connects to ec2-54-243-153-163.compute-1.amazonaws.com  (54.243.153.163:80)

TCP (HTTP):
Connects to ec2-54-213-173-59.us-west-2.compute.amazonaws.com  (54.213.173.59:80)

TCP (HTTP):
Connects to ec2-52-10-189-255.us-west-2.compute.amazonaws.com  (52.10.189.255:80)

Remove chrome_setup.exe - Powered by Reason Core Security