icreinstall_grandtheftauto_game_downloader.exe

Hata

File Validated

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_grandtheftauto_game_downloader.exe, “Hata Setup ” by File Validated has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the InstallMetrix Software installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.sendapplicationcity.com. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Nis   (signed by File Validated)

Product:
Hata

Description:
Hata Setup

MD5:
c8ffb01b3e50c15ee2537a34aa3de7f1

SHA-1:
11fcd1e12856326701fccf336592424ecfcdab37

SHA-256:
4a05b7903e09c4967af8561d44160056b01dfcaeaae52ed83d73897c83b9b6c4

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
1/15/2025 8:41:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallMetrix.FileVali.Installer (M)
16.3.9.17

File size:
1 MB (1,094,232 bytes)

Product version:
1.4.9

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallMetrix Software (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_grandtheftauto_game_downloader.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/2/2016 6:33:01 PM

Valid to:
2/2/2017 6:33:01 PM

Subject:
CN=File Validated, O=File Validated, L=San Francisco, S=CA, C=US

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112127B04ABA745F034A3BB2B235BBD0A1E4

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:54WAxCGMH40LR+AgKoyiXByynmCywV+/zhwbWDRxwAbNTg5:54XCDe9Vhw93wVkxHB

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8769

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file icreinstall_grandtheftauto_game_downloader.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)