home_plan_pro.exe.exe

Home Plan Pro

Home Plan Software

The application home_plan_pro.exe.exe, “Home Plan Pro Setup ” by Home Plan Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.homeplansoftware.com and multiple other hosts.
Publisher:
Home Plan Software   (signed by Home Plan Software)

Product:
Home Plan Pro

Description:
Home Plan Pro Setup

Version:
5.5.4.1

MD5:
0c4860f619d221666cf2572def8ff3c6

SHA-1:
23f50e0976a0c98a03a5d59b213c87e52d9ef455

SHA-256:
9a625cee02767e5fe392f39be93a6734ae7a3e3cd58f197a04f9469c5e036fc3

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/28/2024 10:05:28 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
17.2.3.11

File size:
3.6 MB (3,812,440 bytes)

Product version:
5.5.4.1

Copyright:
Copyright© Home Plan Software 1990-2016

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\home_plan_pro.exe.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
3/27/2015 3:00:00 AM

Valid to:
6/20/2017 2:59:59 AM

Subject:
CN=Home Plan Software, OU=SECURE APPLICATION DEVELOPMENT, O=Home Plan Software, L=Mokelumne Hill, S=California, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
74124C6BB992851F8AECFF3656F040D8

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9975

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file home_plan_pro.exe.exe has been seen being distributed by the following 2 URLs.

http://www.homeplansoftware.com/.../hppro.exe

http://www.homeplanpro.com/.../hppro.exe

Remove home_plan_pro.exe.exe - Powered by Reason Core Security