flightsiminstaller.exe

Wecan Software

This is the Verti bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application flightsiminstaller.exe by Wecan Software has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the Verti Setup installer. The file has been seen being downloaded from inst.bestsw.net and multiple other hosts.
Publisher:
Wecan Software  (signed and verified)

Version:
1.0.0.22

MD5:
ae5e0f64e5861ae237cc393997488c9b

SHA-1:
dce544f940c378e6ba5926e9b1fa7fc815f8b31a

SHA-256:
0cbe9677f17b33d47c4a3f5a3d70866f208ba1078f557773771cb3789f8a449a

Scanner detections:
8 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 1:28:26 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Wecan
2016.0.3221

Baidu Antivirus
PUA.Win32.Verti
4.0.3.15123

ESET NOD32
Win32/Verti (variant)
9.10804

McAfee
Artemis!AE5E0F64E586
5600.6877

Reason Heuristics
PUP.WecanSoftware
15.1.23.5

SUPERAntiSpyware
Adware.Verti
10099

Trend Micro House Call
Suspicious_GEN.F47V1120
7.2.23

VIPRE Antivirus
Rocketfuel Installer
35292

File size:
246.9 KB (252,776 bytes)

Product version:
1.0.0.22

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Verti Setup

Language:
English (United States)

Common path:
C:\users\{user}\downloads\flightsiminstaller.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/22/2014 5:00:00 PM

Valid to:
7/23/2015 4:59:59 PM

Subject:
CN=Wecan Software, O=Wecan Software, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1FD8A9E8CBFDDB2724A69194C505EF77

File PE Metadata
Compilation timestamp:
11/20/2014 12:05:59 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:/I+SAxEPy5n6PMwdnXyuxiG3WK/DlH/YRw7pupJVwhxiWoS4fU2roR:QqEPysl9DiGtlwRXuh9oS4fU2r2

Entry address:
0x1693B0

Entry point:
60, BE, 00, 40, 53, 00, 8D, BE, 00, D0, EC, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, FE, 75, 16, 00, 57, 83, C3, 04, 53, 68, AE, 53, 03, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Entropy:
7.9102  (probably packed)

Code size:
216 KB (221,184 bytes)

The file flightsiminstaller.exe has been seen being distributed by the following 2 URLs.

Remove flightsiminstaller.exe - Powered by Reason Core Security