emulepc_setup_v1.0.5.a0.1_30922_966_stub.exe

ELECTRONIC COMMERCE FACTORY, S.L.

The application emulepc_setup_v1.0.5.a0.1_30922_966_stub.exe by ELECTRONIC COMMERCE FACTORY, S.L has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from cirepo.s3.amazonaws.com.
Publisher:
ELECTRONIC COMMERCE FACTORY, S.L.  (signed and verified)

MD5:
0606dd5e75734e5d14ccf6c73f8c9169

SHA-1:
8cc2b90a8369d15194095f7ecdbd47754d36c06b

SHA-256:
6f7a431c13e4e07fc7e16777b6bc9eb0e9641833e485d9b36731c4249897b1d7

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/28/2024 3:59:14 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.189.104

AVG
Generic
2015.0.3275

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.141129

ESET NOD32
Win32/InstallCore.QF (variant)
8.10798

Fortinet FortiGate
Riskware/InstallCore
11/29/2014

McAfee
Artemis!0606DD5E7573
5600.6931

Reason Heuristics
PUP.Installer.ELECTRONICCOMMERCEFACTORYSL.e
14.11.29.12

Sophos
Generic PUA IM
4.98

Trend Micro House Call
Suspicious_GEN.F47V1127
7.2.333

VIPRE Antivirus
Trojan.Win32.Generic
35230

File size:
1.1 MB (1,130,384 bytes)

Product version:
1.5

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\emulepc_setup_v1.0.5.a0.1_30922_966_stub.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
8/5/2014 2:00:00 AM

Valid to:
8/6/2015 1:59:59 AM

Subject:
CN="ELECTRONIC COMMERCE FACTORY, S.L.", OU=IT, O="ELECTRONIC COMMERCE FACTORY, S.L.", L=CASTELLON DE LA PLANA, S=CASTELLON, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
54C2423D8C2DFF66B2FDCD2A0EA98503

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:CFvZJe2MouF7VrrT5HaO044HeDp3eGBijOE3psEp92Mkus4TuiZx:CZ+FVrP56OT4HeDpXM3psEaPuRBZ

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file emulepc_setup_v1.0.5.a0.1_30922_966_stub.exe has been seen being distributed by the following URL.

Remove emulepc_setup_v1.0.5.a0.1_30922_966_stub.exe - Powered by Reason Core Security