icreinstall_finaltorrentsetup.exe

Baromaroro

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_finaltorrentsetup.exe, “Baromaroro Setup ” has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Product:
Baromaroro

Description:
Baromaroro Setup

MD5:
029ace7ac2b867888d7ecbfcf1d50f7f

SHA-1:
a9e6c9ae4a84492d72d3f6bff57c4c5fbf5563cb

SHA-256:
895613ea857c6640868ae8384917bc6e00ae340b3838d0745b187d2a98761796

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/15/2024 3:44:17 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.RE.Installer (M)
16.5.16.13

File size:
1 MB (1,052,999 bytes)

Product version:
2.5.8

Copyright:
Fast Wizard Software

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_finaltorrentsetup.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:iHsXdMZjAomR9Ev5OusSFoaa9x1rk8+rzEv++0uacyC:iMtMZjAlHEvOSFodNrP+rZ+gG

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9187

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file icreinstall_finaltorrentsetup.exe has been seen being distributed by the following 42 URLs.

http://www.safeupdatenow.com/WVl6OTRQVU5aZEZwMmNIRllhbWhoTldjbE1rSlFkaVV5UWtoUlEwVjJZVlE1Y2xwWlNGUXpVMGcxTkdOME5rMUZjVU5OSlRORUptTTlOWGhIY1VGTWNUWlpRbkJaYTFoUWEySWxNa0pMYm1WVlpsUkJNVTlVYWs5SFRVcDJNakVsTWtaTloyaHBKVEpHVjNWbmJtUjZKVEpDVkZwQk1tSWxNa1l4YmpZbE1rSlNWR3BKSlRKR01tMVdTazFQT1NVeVJuUnJTbWRyV1daeUpUSkNSVTE1YlU5eE9YRXdUMDAzTkhSQk0xQmxTelpIUVUxWU1GRldTR2hHZGpObmNETlNXRlZFT1cxalVsVlNWbTVvSlRKQ2NEbHFVbXQxVlRJbE1rWXdTRVI0VkRaeVkxVnpVU1V6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxR2FXNWhiRlJ2Y25KbGJuUlRaWFIxY0M1bGVHVW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMEVsTWtZbE1rWjNkM2N1Wm1sdVlXeDBiM0p5Wlc1MExtTnZiU1V5Um1SdmQyNXNiMkZrY3lVeVJtNWxkMlZ6ZEM1bGVHVT0=

http://www.bestsharehead.com/WVl6OTRQVUUxUnpNeldsWk9TVlJHWXpGbEpUSkNWbk0zVnlVeVFuZGxTbVpvVUVWNVEySTNOV3Q0VVRWeE4wUWxNa0phV2pBbE0wUW1ZejAxVEVGalUweDZKVEpDYWxBbE1rSnZVMmcxVVd0b2VEaE1jRkZXYkVodE5FWlZNbU5tYzFwUFdtYzFZVzFvVFhWRFZrMVdSVU0wUjBScGNtNUtjSGx6VWs1QlVIcFVSbmc0YmxkRFp5VXlSbEZZWmxwTE5rWnNXRmhQY1dkc1V6RktKVEpHWkVoRGJGWnZTMDlEVTJ4TFoxSmtlbTUyTUdobk1UVlJRVWxvZWxRelNYVlhSelZ4WW5BbE1rWTBhRVJMTUdzM1QyeGpiRUZvU1hoSWN6UlJKVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFVacGJtRnNWRzl5Y21WdWRGTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuZDNkeTVtYVc1aGJIUnZjbkpsYm5RdVkyOXRKVEpHWkc5M2JteHZZV1J6SlRKR2JtVjNaWE4wTG1WNFpRPT0=

http://www.dlpresenttours.com/WVl6OTRQV1ZOUWxZeVVEUmpZVWhCTUhWWk1GQkVUMEUyU1hkWFpHZGtSMGxsWkZoaVEyOXBTakIzVmtkVE5FRWxNMFFtWXowbE1rSnNVMFIwUm1KdFlqZFRiMVoyWlNVeVJrRnZNak5vYkZGVVpHNXVKVEpHY25OcWQxRnFaU1V5Um1WVE1FcFNja0pKY0djbE1rWlNVRkIyTTNkSlozSkhOMDFETmtweWVHSTFjRlJwV0doSGVIWnZXa3hKZVRaWWQwRjZheVV5UWsxNmRuWjBOVnBPVTNOcmNpVXlSamRsYkhsQ1FpVXlRalZIUkROT1VXOUNORmxHU21Kdk1FTldPRTVyYkZGWU9GWlllVlZqVkZwU2VGWTRaV3cxVlVOc01YZEJKVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFVacGJtRnNWRzl5Y21WdWRGTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuZDNkeTVtYVc1aGJIUnZjbkpsYm5RdVkyOXRKVEpHWkc5M2JteHZZV1J6SlRKR2JtVjNaWE4wTG1WNFpRPT0=

http://www.bitspackagelaboratory.com/c?x=lAUUt425nFTM4PlelYLBtPg73Bzy4bChbDl1wcKRmyk=&c=AKBN8ZwjDPM2fJUSwcFx89doxwoyTzdDyfNZDlohSBU3p7m7ck3 lFHFozAHscKntoqXxJJfDB5O7QbPKwVs4HqCeSvspdrKOE5IzrVxOE8e8Zv2pR4zdBgZXISIGnjPYb8OHV3DCOCSAmPHJ4cJ1 n8ACM054Syrk5NL/1Qg3ZQPT/tpGETm/6ILM8ASiEu&e=0&downloadAs=FinalTorrentSetup.exe&fallback_url=http://www.finaltorrent.com/.../newest.exe

http://www.bodytowersquick.com/c?x=iGhuGv5XcR7aH5AefX97D9ei4/w ItIVEA3xoS0SVG8=&c=2c01wO9Lhu8l6ifhBXwcJ/FDJ2fWmbrax Fi2emywGPgS9QfwTVNEytGqRf5uZ7X9tYuIq2FrAioYpFtf hthLDNUXF729txdHbrF 1n5Kbuz4SJixw3FWoctldo6AL7hyJyRXpM1HTffhuWaIiuyHqP6UXnSxbFjnDpf95B9N3stLdf97rMg 4ivOsDUaiK&e=0&downloadAs=FinalTorrentSetup.exe&fallback_url=http://www.finaltorrent.com/.../newest.exe

http://www.bestsharehead.com/c?x=zhi3L0SOClV4P7S0k1RRtwdXFQwiWYnmJOVRf5 kYHQ=&c=1IJLjbfWp70wAsc4WQMfm/rr6Z zv0sl9LL3q8GNg9LJ6x0h4BLbpweFcQSrfeNcGsdN7puhYTsEcXn5l6mG8m/OQVRwE0OhWlvzT5uilNkDcsczc/KTCxGYBOpfcs1xmBbhr4JuxcUOaQl gYVH9zKhTMOT3gOCz8pXHBbUZ1LFNmSUorAYXDKaCHguMCtP&e=0&downloadAs=FinalTorrentSetup.exe&fallback_url=http://www.finaltorrent.com/.../newest.exe

http://www.softwarecapitalfarm.com/WVl6OTRQV3hYWmtSeVZ6SjZUbVZ6Y3pZMmJFbFRNelJZSlRKR2VWaHNibVIxVkNVeVFsTTJhbUppUVRGelltNVVOVk5OSlRORUptTTlhbEZhY0hsa2VsTnRhMWhtZEhWSmVqVnVjVkJNUlVWVE1GUnVTMFUxZW5wNWMxSmpSbFJNSlRKQ1JUbGFWbUY2UTNwSk0wY3lXVVIxYmpWYWMzUlRiamhtZFhKdFVXcDVKVEpHU2tONGNVaHFNblpGTUhjd1NYUkNiMlp2VjFNeFZUaFBXalJaVDIxbWFWaFVWa1FsTWtKV1JDVXlSamMwVlhoS2N6aDJiMmMxVVhOWFNXVmtNbXRYWjFJbE1rWXhXWGRXUkZsSGRHOUNaR1kwV1RoRWR5VXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFHYVc1aGJGUnZjbkpsYm5SVFpYUjFjQzVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtaM2QzY3VabWx1WVd4MGIzSnlaVzUwTG1OdmJTVXlSbVJ2ZDI1c2IyRmtjeVV5Um01bGQyVnpkQzVsZUdVPQ==

Latest 30 of 42 download URLs

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

Remove icreinstall_finaltorrentsetup.exe - Powered by Reason Core Security