exe.exe

Installer Internet Web

AgileMax (New Media Holdings Ltd.)

The application exe.exe, “Installer Internet Web Setup ” by AgileMax (New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.sendtowersnew.com and multiple other hosts.
Publisher:
Software   (signed by AgileMax (New Media Holdings Ltd.))

Product:
Installer Internet Web

Description:
Installer Internet Web Setup

Version:
3.4.4.8

MD5:
f74643236b03efc4667e142e170522f6

SHA-1:
63e5a31c0b3eae4fcb311b6079e9f3e5c7650c26

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 7:40:24 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.Installer.Installer (M)
16.2.21.10

File size:
958.3 KB (981,304 bytes)

Product version:
3.1.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\documents and settings\bures\escritorio\exe.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 1:04:31 PM

Valid to:
10/30/2016 4:53:45 PM

Subject:
CN=AgileMax (New Media Holdings Ltd.), O=AgileMax (New Media Holdings Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112186313590F7C0AF7C143BC6BDE6200476

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:XKSxgTgYTb5VISBjR4+UL5WwuLCv9yUQ3YuEjHyq8pU:XreTgmVVH/U9WwWCv9yJ3aZI

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file exe.exe has been seen being distributed by the following 50 URLs.

http://www.sendtowersnew.com/WVl6OTRQWEpFUkVaVlMzTnRTRFo2YXpWNVJHdHJVQ1V5UW5KWFZXeENlVXc1SlRKQ2JUUkxSR3RpZUhONk5sQnRUbkJ6SlRORUptTTlPVkpTV0hGSlRWQkdkMFpGUTFOVVptb3dTa2xoYVdOcVVVOUpTVUVsTWtad2RuUmxkbEJWYTNSM00wdElNVzFZU0dSdmNVdEVhRWRZVjBOVVdGRkpjVnBEYW5wT2JYRlpZbFJ0UWtoQmNuSkVhM1UxZVhReGFEZG1Ta2hNVVVGbFNIUkZiRzFvWTFOVU1HWTVVMlpHUm1WcmVXMUtlbEp6WkU0MWNteENkSEk1VUhaSVpTVXlSbG9sTWtablRUSnBkVUp4VjNWT1duZEtlSGQzSlRORUpUTkVKbVU5TUNaa2IzZHViRzloWkVGelBXaHZiV1ZpZVcxbExYQnliMmR5WVcxaGN5MW5jbUYwYVhNdGJtVjBMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um1SbGMyTmhjbWRoY3k1a2IzZHViRzloWkhOd1p5NWpiMjBsTWtaMk1pVXlSa2h2YldWQ2VVMWxMbVY0WlE9PQ==

http://www.sendtowersnew.com/c?x=gkk8FDadpR8sMBgDSzSVuhWmkE73ws/T/yVtzGk1ZOg=&c=VbYhfQZKCN3FUq6enhhOlMS9XzqcHx5 NfEgzLTiIqnMwvdz2Sj03Q7JHZ0i DiwyvUkfMryPLEKL8NAEVCua04b28yEb9ywXy7E0TPrXui RqpRbKuW2MW/KlBrr QdQhDDHNlMv3eSGGq8aCnxNk55jg7XYM024SI533aVpC0UP0rJt7otSQ7nK25wJktK&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

http://www.sendtowersnew.com/c?x=hT6cnNF2GiAQTGLOathuz27SVGeiSjp621eZnLiiA/Y=&c=dTPGlp uaQKwoQzRepqShTNwgZ 4hyaM7dDF8CPWrnhLxw5nmW9qh/Mh9Iv2On2euXVLb/iKjbqddj3DS zm55LvY3xPnYqYem5yD5RCBrnshLoOsj7Ph4V1Azpcp1Y2W5RWrsUpqUA65MJGTYYi1MMRcZSf28Izo5d1jd7AnJE=&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

http://www.bundlecentralbulk.com/c?x=QBejdjPF7WD 3YM8KF726NT9GhNMmIBKRUnARGmLeJs=&c=GkzJpPQ3y2wTVEkVk2zHjT/AlKD0NuL8KAMTgTdfvnJPfYY43Ach AepzcrPepBjTJm4A/MlZnozuRUXhrkUoBvBB1RlgVp9Tjp5avAv1QVOgXttse5ZGkEwbjmCFzMzMgO7ZInjnb Xl5EvR1Ce4QF5EukuKaXhzKeZLaGXTzY=&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

http://www.bundlecentralbulk.com/c?x=7qcBzo9QCHo9btsVNQHmTyANFgQEJfWQHYpwg77vxm0=&c=iMgK4KEKWMKMgEqJrpIU2f0a8Ngr72rT3CQGdrIEMH8sqHdzOhcztxBFKmaVBzFhto0TO/JKkt0pxfR uhTfHbG2SFdFEJm4p9P1j5fIM9dymMj8WTaPJJCL5H8dQGtmZadTcuM5zBJbnXsqfFqeJs32VE0qi8nY9TYkmamRok8=&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

http://www.sendtowersnew.com/c?x=MT/9we/lNMtl7M6ug7kORk95IPB4Pl86ely64y PmbA=&c=bJrjwwsJtenEOzAE 0U5ADeif3tz2Bjkv6CWRaiAUACdJgXmaqS8Wrb5j3PpaOD4oZxScACtsUNshfI9pfNgR8PP5i1PJmDhseNmLx1Jobr6mTTiNRXCJyMz2Y3qgTq2h0HHLA4HhZtJ0AP5smB5Pp6GEu6UiZqNFgXIp4NBag0=&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

http://www.sendtowersnew.com/c?x=KsE2EzLBC14WmPvlW/uV6IOr4jI1vUGAsyrzH36Z63Q=&c=DkCGu6IC 48 panPp7pCIYq nI7wlhS90gh8C2cCpyA0rE1Fio8uDdCEqrWRMQjurCvPC2GNmN1Metcq0w9IF3jNoiZMyy8RG9hbwXvaM2zJAZSmeJraMhWgivBzsJg3jnxp8hhoFvDT011rDVwNSf3S1bVFaZBwfCtEHpJp7yFcUg2b/1gcVjUnoJWhi/9y&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

http://www.sendtowersnew.com/WVl6OTRQVTFxVEZsT2VqVkJhbkZqVm1GUk5tbDVTMEpEVnpZeFFuUWxNa0o2ZVVKcVdrRkxNMjlGVG1WV1FtbHBUU1V6UkNaalBXZDJZa1Y1YlhwM1FYRkxlV3NsTWtKcGNqZExkbGx6Vm1RbE1rWklTbTV3TkdZMGRTVXlSak56SlRKQ1dFdGFaRkphYzBocFl6QlNWbUYyU0V4U1NFeG9OelJHZFUxd05VRmFXVkl3VDBKU2RISlpWbUVsTWtKV1FXZzRWRnAwSlRKR1NtbzFlRUZJVldsMkpUSkNXRXc0ZVUxemVsRjNVSG9sTWtKWWJTVXlRaVV5UmxaYU5URmlXRk5wYVU1YVFtbDNUV1F5ZGtsVmNtbE5VMnBRYWpWM1MwUjJkbko2WkZsUkpUTkVKVE5FSm1VOU1DWmtiM2R1Ykc5aFpFRnpQV2h2YldWaWVXMWxMWEJ5YjJkeVlXMWhjeTFuY21GMGFYTXRibVYwTG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJtUmxjMk5oY21kaGN5NWtiM2R1Ykc5aFpITndaeTVqYjIwbE1rWjJNaVV5UmtodmJXVkNlVTFsTG1WNFpRPT0=

http://www.headsignchuckle.com/c?x= ttupZr9oaPTWU8CitU17Ba9q6ziT7mUaLlVPFboWSI=&c=c8mUOJ8L2gfx40DwE0Qrs5QGABIQoHpFwB9KsvFfJzMGa4UxZQ3o2NKKz/u AVKY2vkP9n3s4eIEiMAd20TdPvQFsvw6BHbOXLRjcUGgJZWvAqIBHLNjUjhsh/JnBdjYciy5xK9Bffr0LnYuOb1dZbSM/3qFv7ALQ4FRmjJO8Cc=&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

http://www.sendtowersnew.com/WVl6OTRQVkZKT1dodGFHSkJPSHBxSlRKR2QyWmhaRFpFVFVoR1FYTktiVVY2TUdnek1WaGtRVWRUWXpWemJUbDVNQ1V6UkNaalBWRjBNVFY1UTBzeVlrRndKVEpDTUdSSFJFWlNaWE5hUVZwV2RFbDVaRXRzVVVkT1ZYWk1aeVV5UW1WNk4zVkRXbmQ0U1dwblJteDVXREFsTWtZbE1rSmhkSGN3TWs1TFNXNWlPVVZ6V25waWFXbGlVSEEwTW5vbE1rSk9XaVV5UWtoM2RGQmFSbHBZZUcwMFVqSkVlSEJxTWxGNlVWUnBUa0o0ZFdKMWFuSnhZekI0Y1RkRmRVTnpiRUphSlRKR2NGYzBTQ1V5Um1JeFJtdHNSREZFTTNoVFJ5VXlSbFphZHlVelJDVXpSQ1psUFRBbVpHOTNibXh2WVdSQmN6MW9iMjFsWW5sdFpTMXdjbTluY21GdFlYTXRaM0poZEdsekxXNWxkQzVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtaa1pYTmpZWEpuWVhNdVpHOTNibXh2WVdSemNHY3VZMjl0SlRKR2RqSWxNa1pJYjIxbFFubE5aUzVsZUdVPQ==

http://www.sendtowersnew.com/c?x=Ali67S8aqFb1Ynv/qSgnuzv4Knsbagi776bDGNNNqWs=&c=qyVd9Mb4uMWEATUi9DOvno2GDXI3AEUe6WMaF95MUzWfKSCgAS61qn1gME9T t7XbMU2oOx7P70mD5R62s22S Z5NbpzGr0pORB8j7tWwMk44kohHYVf5AxIKUtfDytuFS7WFmbyZ6NyOZ3OaPYqLBgD900KZOhWKOHsXyf6npqMe5npQ2JJ/hM/L5ge6Ec6&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

http://www.sendtowersnew.com/c?x=UqsaAWya/APwANfkZFRDKTqwGym7CLCOT16gco/bh6U=&c=4kPuPHxcnYLweZE0SGwCDTAxxl7AjzDW ffiknTNluYQkvvvSjhsHQOV7HN5ht5auxW8wyUDXjzK9GyvALoq8ogBwDo1CgLfEiJtR2KI6zzMKjxDNW0zYVQ/RWlYtPAaAf09beZMj/5jFyLP7rF94iAqpXUbl9QszTOHV07SDikuz0Ab2LhCdlovwagsBnPP&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

http://www.sendtowersnew.com/c?x=MnwRJPgnQEizTir2qkbSER73jEgeXK2ZtVfX9ORn/fQ=&c=vVGUz7MAOrdpwiejakBYTADuTh QC1amYE51HLOBee9Kj6FoHSYW01LyHrtRbE9WdPCvGVWOk/ed9XxQg2fVbNjsHvpSGjDRyimM2JZ0w4tjeWVeH/y9w1qoxEEkAB1z3CtVEt3eZPY1FFqqKq9vBZDbw6cdSRb0yUYqjYiqQwY=&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

http://www.bundlecentralbulk.com/c?x=ZtD5xA9AUGCfCNCXIFlcGNpS7LXsg3hwQ 7eaO86/pw=&c=zbGMMKNXdogBaT99DbrRQLJDAqLcaX3TZMXRVwvi5HPmELfjm1bNs8wyMjpkbYVwNBS15B4Su1I71Logk2UU7qG8W4DsHNZDbutalkHk8MSLTxtwPdAEPkNqoKcPRarZEwWD54d3rDfe5FWq3fgU06h0oBS FDeEfy4YlLZi3oo=&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

http://www.bundlecentralbulk.com/c?x=6 tmXDssoPwefRhguahRmlTUou pCfaDY9YESJJyDeE=&c=gZhwbis1a4H5ngGJW1JO8MxyeYhmd6e4cy0Uj5H7UgH72fnUqKT7VYMGlVMVZwGQmSW0mNIdeXmJnAoCLmZMEclpp9rVEUgfYgdBDaX nRMG11GgROWH0fUiGfvPDILKg0bZ 3qQzAYjm2U9K8rQzc/E ELw6bv7g/c4tK36KxU=&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

http://www.sendtowersnew.com/c?x=sVrFKowqjXyFBUyyYA/WRxNQuhuUAOStajXrELsj9OM=&c=FZ7S/2Dwk5oe3wxYt aPKSD2Qfyec39XvBJyilekzgaJzihmSjNmzutFyHPob8mFOo6MSSSBsrgCKdP1pJJsegM5ldPg5pcK Wn2PxJvn6oRtXnwVl7jt1qEHXQ1vJJ0x66oiWpw1YEvvRo2p33iQj8JKiIMH/nAmhHG/WtbOPU=&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

http://www.bundlecentralbulk.com/c?x=zAnCZGKGEuFkCAlQKkLehiZSXLz0zPw2mijbUb7 iQQ=&c=p03GNNPPVWcH5wD/uGaFL1VZmLm8hQCW6HGXVcbd5ALOdHXr20Lz6myRRKxG41PnUyfDyu AiK5T1Dgc OhFKo2 RcTczbV8M41wcYZX DqkwwVqNTpGRRbsJHHP0MXXwjUZzDFVIRjKWhDPwKDh5AOM1c0uYrUTAxBVgpZUgV8=&e=0&downloadAs=homebyme-programas-gratis-net.exe&fallback_url=http://descargas.downloadspg.com/.../HomeByMe.exe

https://prod.squareclock.com/.../download.php?HomeByMe.exe

Latest 30 of 111 download URLs

Remove exe.exe - Powered by Reason Core Security