computer_bild-download-manager_fuer_dropbox_2.6.27.exe

COMPUTER BILD Digital GmbH

The application computer_bild-download-manager_fuer_dropbox_2.6.27.exe by COMPUTER BILD Digital GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Covus installer. With this installer, users are expecting to download Dropbox but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware. The file has been seen being downloaded from r2.computerbild.de.
Publisher:
COMPUTER BILD Digital GmbH  (signed and verified)

MD5:
dca8e3a9e857836585ee262ebe33e87a

SHA-1:
b1e92732d3c263afb8922ce9143ed6e8222420f5

SHA-256:
9cfaab0f0e0a6f512a50d44da6e26b957f443d50be8dc8d8e0ce98cff3a718ab

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/2/2024 1:25:41 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Covus (M)
16.8.4.14

File size:
692.7 KB (709,352 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Covus (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\computer_bild-download-manager_fuer_dropbox_2.6.27.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/9/2014 1:00:00 AM

Valid to:
12/25/2015 12:59:59 AM

Subject:
CN=COMPUTER BILD Digital GmbH, O=COMPUTER BILD Digital GmbH, L=Hamburg, S=Hamburg, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
727178E5F63BC61D108FA7070AF55522

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:CvpP9dbSQ3CvuqV7IxoiZsJtY29Nslenou5/LDhN46jbtKfIiQt58GqFba:Cvx9dTCvpexoiZsQ2jqeoU/LD8q5uIiV

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file computer_bild-download-manager_fuer_dropbox_2.6.27.exe has been seen being distributed by the following URL.