icreinstall_ccleaner-13061-dp.exe

Fas

Docesipete

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_ccleaner-13061-dp.exe, “Fas Setup ” has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer, however the file is not signed with an authenticode signature from a trusted source. With this installer, users are expecting to download the free Piriform CCleaner but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Docesipete

Product:
Fas

Description:
Fas Setup

Version:
4.5.4.0

MD5:
88f9fa8366c0a2dde77e98fa98b06adc

SHA-1:
980ab7c5884cad74fb08450b25f15ebbfe79c1e9

SHA-256:
589bb5c151160930ef9f38821b78e98b4730e4ba44162a37641b11ec13db6d18

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/16/2024 1:23:04 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.Docesipete.Installer.Meta (M)
16.2.29.9

File size:
1.1 MB (1,112,881 bytes)

Product version:
1.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_ccleaner-13061-dp.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:6RdMs9NnAHY4gDGedk9OA/G+J6bOBZJfWSNSFKFW4wefTE:6b5jAHGGedkYA1T4KFW4wgE

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file icreinstall_ccleaner-13061-dp.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_ccleaner-13061-dp.exe - Powered by Reason Core Security