icreinstall_format_factory_4.0.0.0.exe

Fast Lite

International Data Group Poland S.A.

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_format_factory_4.0.0.0.exe, “Fast Lite Setup ” by International Data Group Poland S.A has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.quickfarmbundle.com. While running, it connects to the Internet address interest.monitormaildepot.net on port 80 using the HTTP protocol.
Publisher:
Fast File   (signed by International Data Group Poland S.A.)

Product:
Fast Lite

Description:
Fast Lite Setup

MD5:
5feefdb0e0a5ec4a5d727cf3d1449d8f

SHA-1:
94d2c327e05d45d88bc41a163e13dec2e12fae7a

SHA-256:
e9c2af9b31e9f0539c4c00f5473b9ce0e9685280f0d6e6c829e5165e27c62d08

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/23/2024 12:46:18 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.13.21

File size:
1.7 MB (1,816,200 bytes)

Product version:
5.5

Copyright:
Wizard Application installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_format_factory_4.0.0.0.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/30/2016 3:21:17 AM

Valid to:
8/31/2017 3:21:17 AM

Subject:
CN=International Data Group Poland S.A., O=International Data Group Poland S.A., L=Warszawa, C=PL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G3, O=GlobalSign nv-sa, C=BE

Serial number:
64A80379DAA3514FAED45E16

File PE Metadata
Compilation timestamp:
1/30/2013 6:21:56 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9591

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file icreinstall_format_factory_4.0.0.0.exe has been seen being distributed by the following URL.

http://www.quickfarmbundle.com/luUHCB_0xqfbBFIwZ9OvlrxaMAfuYeSSdfGFVTKKcK0EP_JBU7g6FHaK8ONzc8zYe7ZJgAyOv EGo4YJumnVln3LtWOI5YXojj5F1RlFF UNv8u0G2siDGWOx5peBmuGsIfQO66s4bmaQHPJd8TlA_jgD9iWTlWqI4Hc1jgDR714s1VmI3TvP6ZdLlnQK0MXzEpv6w 3qJPZcpecXlKVSkM830U6lJSR3A4Md7k2B9w8afTPDo 0rTuWKjUqB6rVKFBGpQIkrXiv7wOXBRCZ4dq8aFnQGPLHx K28tL3iMjgut0f_F_EEmWHk4aG30FedZY2HzQgGuxiF8bwoGeX14msGhe2cMRNYywhhN2XDZzNgzaoaqRq2T20ocU7QTYAKChTeww9Zs1FqF2OMBLjsME58XFoW9GO33 gyT6 lh52FdiWr35IQ4TqDApLHrJVRk_UVyfgiut7 v28qx0yv6_F9PYQA2Zo6dMJc0PLNPEERaz1Kcd1ATLRRbJmzMmBQOCaKy9lXU7F8YcCApI1D_wf7blcjr_Ms0V9bCqUWFran75sYnA0_QAMu1ZYRW9si75XR5m3RKo1bp3qomUO7nCNZTJIEvTW7hXjc7KY1u3I0_3xs vkzu7aZS51hCXB1QO8ap_i-GzIAAEQnh_aCgA8SYLsfags24IC9H2QcTAcPWagPTCDIGzN PT6qGjnwgmztuZCcXg==

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to interest.monitormaildepot.net  (67.229.68.202:80)

TCP (HTTP):
Connects to ec2-52-49-170-39.eu-west-1.compute.amazonaws.com  (52.49.170.39:80)

TCP (HTTP):
Connects to ec2-52-214-247-42.eu-west-1.compute.amazonaws.com  (52.214.247.42:80)

TCP (HTTP):
Connects to ec2-54-154-229-88.eu-west-1.compute.amazonaws.com  (54.154.229.88:80)

TCP (HTTP):
Connects to ec2-54-154-190-87.eu-west-1.compute.amazonaws.com  (54.154.190.87:80)

TCP (HTTP):
Connects to ec2-52-2-72-151.compute-1.amazonaws.com  (52.2.72.151:80)

TCP (HTTP):
Connects to ec2-34-198-66-66.compute-1.amazonaws.com  (34.198.66.66:80)

Remove icreinstall_format_factory_4.0.0.0.exe - Powered by Reason Core Security