httrack_x64-3.48.22.exe

WinHTTrack Website Copier (x64)

Open Source Developer, Xavier Roche

The application httrack_x64-3.48.22.exe, “WinHTTrack Website Copier Setup ” by Open Source Developer, Xavier Roche has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from download.httrack.com.
Publisher:
HTTrack   (signed by Open Source Developer, Xavier Roche)

Product:
WinHTTrack Website Copier (x64)

Description:
WinHTTrack Website Copier Setup

MD5:
01e70ea7ff6ad9eb32d3cf41de802823

SHA-1:
61cba06286d768d6d172edba4cad2b0c09f4ae1e

SHA-256:
faaaeec402ed04aa6da7ec5b28bfd36c7be0f2307a29d13c44637b1fd9c26860

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/28/2024 4:23:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
17.1.25.11

File size:
4.3 MB (4,498,888 bytes)

Product version:
3.48.22

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\httrack_x64-3.48.22.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
9/10/2015 7:05:16 AM

Valid to:
9/9/2016 7:05:16 AM

Subject:
E=roche@httrack.com, CN="Open Source Developer, Xavier Roche", O=Open Source Developer, C=FR

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
54E9B69B61DD79D740AF1361D6827F37

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file httrack_x64-3.48.22.exe has been seen being distributed by the following URL.

http://download.httrack.com/cserv.php3?File=httrack_x64.exe

Remove httrack_x64-3.48.22.exe - Powered by Reason Core Security