icreinstall_grand-theft-auto-online.exe

Cir

Destiny Dream S.A.

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_grand-theft-auto-online.exe, “Cir Setup ” by Destiny Dream S.A has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.appstowncity.com and multiple other hosts. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Minuho   (signed by Destiny Dream S.A.)

Product:
Cir

Description:
Cir Setup

MD5:
e99513e12ae89321770299666852cdf2

SHA-1:
afd400d2dc30d0c3d635baeb3e6a2cbd0d9aea45

SHA-256:
3e23bc27c8dbd321dd0a5b8327e4f3ad6f6347028368235d99b4269eafa5749d

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/24/2024 5:27:01 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.DestinyD.Installer (M)
16.3.27.17

File size:
1 MB (1,078,040 bytes)

Product version:
4.7

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_grand-theft-auto-online.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 7:55:11 PM

Valid to:
10/2/2016 8:36:18 PM

Subject:
CN=Destiny Dream S.A., O=Destiny Dream S.A., L=Clarens, S=Vaud, C=CH

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11217A75EB912AE2167326222C18D9E2357F

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ubmjb2rfYLfQazIgBOg5h3bMqDyrRupNCMvE6G1NFYZVSmc8AR:uS7cazIgBOg5dbLyZMcoJu

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9068

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file icreinstall_grand-theft-auto-online.exe has been seen being distributed by the following 50 URLs.

http://www.appstowncity.com/c?x=L2zSYUyRKqC7OSrAzSGoR2yHl5cogNDSiYYqHCZ8i8A=&c=CAi8UbQQILcplv0 wzRKv9lY3jbVccPBO2y6/2R/1TIv1gDuGWrzZStL UtTyz8y5 uqHbMJ0WdiDGQnrPss3lPyll wjZgH5n9sNSm63ZJHXI8MFWWRQIggyC/FMy6dHSNuU1 sa6d5mGQjIlrieg==&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

http://www.vaultsdeliverycenter.com/c?x=NjKA65onl6Hdm6onSuxcp/95z1NcJOvviXge4B5nCVs=&c=M/Ba0HmtrHIqeIWICNJd1tIMV/66Qh5PvRHLXBZHiXeXr j2M1VhB6RduY5QqoJvkr1rvaP yKLpDXTeSakceNwpdKBe 4VxXcLRCwQ9q/LX 7T0ZyNJXDxh9SB2SgLJCkV2JQ7AbL1mLeTdyG7KVq1O/f3jqggZbVBGnHgXAtg=&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

http://www.appstowncity.com/WVl6OTRQVGcyYkd0eVVITmFkRTFxVlU4MVJXMWFOWEp6YjNoVlprNGxNa0ppYVV0Q2JHbzBURUpsT0dsMFZ6SjVWU1V6UkNaalBXOGxNa1pJZFdwTFdqTXhaRVJSUkRRNGIyRkhURFJTUVZCS1Vta3pVVkZRUlRKaUpUSkNTRVpDUkdjeVlrSk9XVzEyUjBSUWNVWkRUU1V5Um5VelMwZERjRmRLY0RKYU1ra2xNa1o0UW0xVVUzSlBXVzkyTnlVeVFqZHRkRlV4U1hsbU9WTXhWMU5pVmtwbldFMXJUWG94ZFRCcFdETjNWRGx1U1RocWNDVXlRa1pQZEhSaU5ESkdSMEo2VFhoNlRqQnpObTFoWmtSS2ExRTVObXBQYTBaWlp5VXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFuY21GdVpDMTBhR1ZtZEMxaGRYUnZMVzl1YkdsdVpTNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1ozZDNjdWNtOWphM04wWVhKbllXMWxjeTVqYjIwbE1rWldKVEpHUjFSQlQyNXNhVzVs

http://www.vaultsdeliverycenter.com/c?x=HcwsJC515SA5vcIHVmkAO8U/GjQmKG5AplGMF4UlhQc=&c=5xxKYYRY0wc4lUGFDxivuWFm2IjVzofK6ttfe2kPh2z/ehrj9tlGcOXQh x38y2nxdJ4ZpxzdBG7CWfh5sn6nP5hsQd5ORWqa2EgY4Re/tdwPqY19LADmGMeHQq1axh5ptGL8Tz5JYBZ2wBFt1s 5buu9vXAAkxjmWIWh1YUYwkKVDjBi6jhMHtmoKc6ZVJh&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

http://www.hostingtagbody.com/c?x=HR9Wxrrd9jawsMxZvTdrlfhUykJjc8mp/6hm63nPLYg=&c=MlF/aHvTfH8AliwLL kEPtcgfnE3FGqPQQkib/lRaBxylx3166/zCBOv8D9ofA9069W6oTW TO6S214Xv3AR9lVrwJ3cyOXLcjaoWp5u8Kz0fTafT23l/y3T7VfWdhHCykoECs6W2x68sYoUD9SPYw==&e=0&downloadAs=grand-theft-auto-online.exe&fallback_url=http://www.rockstargames.com/.../GTAOnline

Latest 30 of 64 download URLs

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_grand-theft-auto-online.exe - Powered by Reason Core Security