datafaktury_setup.exe

Data Faktury

M2Dev T.Jankowski, P.Nowak Spółka Jawna

The application datafaktury_setup.exe, “Data Faktury Setup ” by M2Dev T.Jankowski, P.Nowak Spółka Jawna has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.poldata.pl.
Publisher:
M2Dev sp.j.   (signed by M2Dev T.Jankowski, P.Nowak Spółka Jawna)

Product:
Data Faktury

Description:
Data Faktury Setup

MD5:
2e8616925402d2925f0a8be9139ec191

SHA-1:
b63fbfb4e847914d095cfd155b67366549c73256

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/26/2024 12:26:26 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.28.10

File size:
17 MB (17,811,224 bytes)

Product version:
4.1.0.1

Copyright:
M2Dev sp.j.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Digital Signature
Authority:
StartCom Ltd.

Valid from:
6/9/2016 8:37:01 AM

Valid to:
6/9/2019 8:37:01 AM

Subject:
CN="M2Dev T.Jankowski, P.Nowak Spółka Jawna", O="M2Dev T.Jankowski, P.Nowak Spółka Jawna", L=Dopiewo, S=Wielkopolskie, C=PL

Issuer:
CN=StartCom Class 3 Object CA, OU=StartCom Certification Authority, O=StartCom Ltd., C=IL

Serial number:
1291BC2BBB1BE03AD64C40A7C2D5960B

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file datafaktury_setup.exe has been seen being distributed by the following URL.

https://www.poldata.pl/.../pobierz.php?filename=f_586385e0000e8&real_filename=DataFaktury_setup.exe&mail=&info_o_m2dev=1&info_o_mf=1&title=Data Faktury Lite (darmowa)&version=4.1.0.1&rozdzielczosc=1536x864

Remove datafaktury_setup.exe - Powered by Reason Core Security