icreinstall_apache-openoffice-12754-dp.exe

Internet installer

dobreprogramy sp. z o.o.

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_apache-openoffice-12754-dp.exe, “Internet installer Setup ” by dobreprogramy sp. z o.o has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. With this installer, users are expecting to download the free Apache OpenOffice but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Web Installer generic   (signed by dobreprogramy sp. z o.o.)

Product:
Internet installer

Description:
Internet installer Setup

MD5:
3ce0407a5770f2a6e90e73c5e374b7af

SHA-1:
79301e164bacc022c2f2bf23ff058c3bbf8448ca

SHA-256:
3c32b57768183b38362a82cd56fac09ddcf9be8e569d5984b28908ddc0aff182

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/30/2024 8:58:11 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.dobreprogramyspzoo.Installer (M)
15.12.17.15

File size:
846.4 KB (866,744 bytes)

Product version:
2.0.6

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_apache-openoffice-12754-dp.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
2/24/2015 5:00:00 PM

Valid to:
2/25/2016 4:59:59 PM

Subject:
CN=dobreprogramy sp. z o.o., OU=IT, O=dobreprogramy sp. z o.o., L=Wroclaw, S=Dolnoslaskie, C=PL

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
04CCACE3AEB4566AFA610407D3C9D967

File PE Metadata
Compilation timestamp:
6/19/1992 4:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:hEIue+LAYj8URLR+lhbRCUKwSsid8GVMdvBGx8NTWC:hTyLAYrRLWRCUBSBVMdvh6C

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9172

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file icreinstall_apache-openoffice-12754-dp.exe has been seen being distributed by the following 2 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_apache-openoffice-12754-dp.exe - Powered by Reason Core Security