icreinstall_internet download manager 5.11installer.exe

Kopig

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_internet download manager 5.11installer.exe, “Kopig Setup ” has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Product:
Kopig

Description:
Kopig Setup

MD5:
dac71c88002b357fa78ef92e7b946cf9

SHA-1:
59a7a79fec7e7714483f860c4b0c3b620dfb8440

SHA-256:
f908494260e8947be4c90b54d6642ca36786cefdd0d7c6c93ad59a244dae46f4

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 8:00:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.RE.Installer (M)
16.3.9.12

File size:
1 MB (1,091,211 bytes)

Product version:
3.8.3

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_internet download manager 5.11installer.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:QNXQHOUE8Vy1GTGYDlui0BGtdjNQRLMYjk2co+bQNiCs3qJfTKGY:QNAuUF7lu5+jNQRokFx+bQThep

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9096

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file icreinstall_internet download manager 5.11installer.exe has been seen being distributed by the following 50 URLs.

http://www.bestcleanshare.com/WVl6OTRQU1V5UW5GcVF6Tm5WalV5TW0xd1EwVkhRa0ZYWVVzM2RHNVJlV0pNSlRKR1luZDFXazlLTVRnMVdrOUtNa2hSSlRORUptTTlOQ1V5UWtGd1dGTktURmhsTURNM1ZEaG5VWEZpVVU1RVlrd3habHBqVWt4aVRraEZKVEpDYVRkQlJUbE5RazQyUkU1RmQyOWlkRWhuV20weE5DVXlSa296WjBGMllXMUtlak53Vm5aamNXZENWR1JtTTJKSUpUSkdhVEJ5VW0xelZFUTBiemxIU21WeVJETnZXVzgxVG5NNGNXUjFSSFZ6Y0dneU5qRkZORlpZSlRKQ05rVklhWEoyYVVScWEyUnlhVmNsTWtaUFdsTXlSazVZZDNwQmFWcDNKVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFVsdWRHVnlibVYwSzBSdmQyNXNiMkZrSzAxaGJtRm5aWElyTlM0eE1VbHVjM1JoYkd4bGNpNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1p0YVhKeWIzSXlMbWx1ZEdWeWJtVjBaRzkzYm14dllXUnRZVzVoWjJWeUxtTnZiU1V5Um1sa2JXRnVOakl3WW5WcGJHUXlMbVY0WlE9PQ==

http://www.conceptsgiftrepository.com/WVl6OTRQVzExYkNVeVJsbDNURVJzYm1sR1NsWllOMlJXVGxOWlVUVlpWemhDYm04MGRsY3dkRWxxZVRkMVQyNUpUU1V6UkNaalBWaElVbU50VEdGWFl5VXlSbWxRT0ZaeVJWQkxSRk5VYjNWek9HNXFaVGcwY2twdmJEZERjbUZDWkdSNmJ5VXlSa0pqTTJ4UVUyODBkbU5ZWm0xUFNGVmpPR1J4VWtNbE1rWkhUWGQzZWxwNGJrdGlSM2x1Tm1kYVNETm1Xa1p6YjFNeFNYUTFTWGx3YmpBNVZISnpjSHBQVVZSTk5YQlpiRVpEWlRGV00xcEhKVEpDU2xoNkpUSkdRU1V5UWtSYVduVlRUVlEwYldGUFNXTkVXblJrUm1kVVFTVXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFKYm5SbGNtNWxkQ3RFYjNkdWJHOWhaQ3ROWVc1aFoyVnlLelV1TVRGSmJuTjBZV3hzWlhJdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdiV2x5Y205eU1pNXBiblJsY201bGRHUnZkMjVzYjJGa2JXRnVZV2RsY2k1amIyMGxNa1pwWkcxaGJqWXlNR0oxYVd4a01pNWxlR1U9

http://www.bestcleanshare.com/WVl6OTRQVFpsYkhkVlZXcFVTbTl0UkZWbVlXSmtZMWRESlRKQ1dqVlRWSHAxWXpkWFowbENNRmxIYnpoamJFdHVZeVV6UkNaalBVOVRaa3QyYVRGMFprNVdTVmczSlRKR1lqUnRjRlppY0ZvemJHeDBhamQ2ZGpjeVkxZHlVVnBVZG5NM2RFZFhOWGw1YlZVMVpFVlNUMlZGYzNkTVEyTkthVEpDTldsclZFbEVkVmhPV2taVWJXWkpWVVp2ZVhwekpUSkdUM0pyUmtSNmVtSmFaMVV6WjFRM2QwWnlNU1V5UW5aalUxRkNWVmhtWWtSTFZXOWFVRTk0ZW5OemR6bEZNazR5VWs1aFpYbzFTRTVNZVhWM1JtUk5RU1V6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxSmJuUmxjbTVsZEN0RWIzZHViRzloWkN0TllXNWhaMlZ5S3pVdU1URkpibk4wWVd4c1pYSXVaWGhsSm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROQkpUSkdKVEpHYldseWNtOXlNaTVwYm5SbGNtNWxkR1J2ZDI1c2IyRmtiV0Z1WVdkbGNpNWpiMjBsTWtacFpHMWhiall5TUdKMWFXeGtNaTVsZUdVPQ==

http://www.bestcleanshare.com/WVl6OTRQWGRNYjFsWlJuQnRXRGRoVDFkS1MxTlBXQ1V5UmlVeVFtbExkVXRQTW1WbGNYUnJhWFpsUTNCT1JGQm1UbVJuSlRORUptTTlSekl5Tm1wUk1scFhlSFJOSlRKQ2EyeDZVekJGYW05UFUwOTFRWHA0Y25SdlFXMXNkVGw1VkNVeVJuUlJkVlpSWjJVM1l6WmxkRGQxYmpsRGRXMXFWMkpKZHpBMFJUaG1UM2h0V0ZSbVMzY3pURVJEZFVkNk9WZDJVMlpFVUc5NVZGSkVReVV5UmlVeVJtbFVWamN3SlRKR1REQkJOME5RU3pKUlRqTldXbFJGV2xoRGMxUm1jMGROVlRkd1pVcGpURVYzVldSMFRucEVVV0pQYTFwRmR5VXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFKYm5SbGNtNWxkQ3RFYjNkdWJHOWhaQ3ROWVc1aFoyVnlLelV1TVRGSmJuTjBZV3hzWlhJdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdiV2x5Y205eU1pNXBiblJsY201bGRHUnZkMjVzYjJGa2JXRnVZV2RsY2k1amIyMGxNa1pwWkcxaGJqWXlNR0oxYVd4a01pNWxlR1U9

http://www.bestcleanshare.com/WVl6OTRQVmQwU0ZSbmVrODBKVEpHUW1NbE1rSXliSFZoZWxSRFZpVXlRamRQV25GSlNrcFdOa1pOVG1kWk1UWldkREY1VjFFbE0wUW1ZejFKUnpKTlVrbzRaRFprWmtOWmRUQm5jMmhrUjNkRFMzSkpRMUp1SlRKR2NVcEdURzFMWlUxNGNqWlNNemx3T0V0Q1N6VkJRbXBISlRKR05raHRkV1pwUWtSS1dEbHFVMlJzUnpBMVYyRnhhbFZQYmlVeVFtcDNPQ1V5Ums5SVFrNUhRMEpJVVhCM1RFdExNbTluZDBwT2F6UnFVa00wVTFkYVZ6RjNZVXhzTmxveFVGaE1TemRyVWpSRFEwVmlORTVUSlRKQ2VqUjZTMk5tVFd0VmMzTm5KVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFVsdWRHVnlibVYwSzBSdmQyNXNiMkZrSzAxaGJtRm5aWElyTlM0eE1VbHVjM1JoYkd4bGNpNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1p0YVhKeWIzSXlMbWx1ZEdWeWJtVjBaRzkzYm14dllXUnRZVzVoWjJWeUxtTnZiU1V5Um1sa2JXRnVOakl3WW5WcGJHUXlMbVY0WlE9PQ==

http://www.bestcleanshare.com/WVl6OTRQVmw1VUd4NlRtY2xNa1pWVDBkYVNXTmlOR3BDVGtKc05IRlJlWGxHZVU4bE1rSTJRMlpGUzBwNE1HWkdOMDFWSlRORUptTTlUMlJEV1NVeVFtMHdZV2RtVmpkV1IxVlJKVEpDY25VNWMwRmFURkowTjNwTFJtOGxNa1p0V0dsNFQxcG5OR0pCWVdnbE1rSnNRWEZTSlRKR2NWcFJaMlUwVjJWbFp6aElTVUZSWnlVeVJsaGlUVlZIV0dseldHTllXR1ZOU1VKWmFXZEpNVkpZYURWb1NGWkVZMVZrTWxVMlRFRm9OM052YmtOU2J6RllSbXRqTmpJbE1rSWxNa1p0WlZwQ1kxZE9TbTQwVWpCQ1ZXdFdiRVZKT1RaTFFtTjFURkpyUVNVelJDVXpSQ1psUFRBbVpHOTNibXh2WVdSQmN6MUpiblJsY201bGRDdEViM2R1Ykc5aFpDdE5ZVzVoWjJWeUt6VXVNVEZKYm5OMFlXeHNaWEl1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2JXbHljbTl5TWk1cGJuUmxjbTVsZEdSdmQyNXNiMkZrYldGdVlXZGxjaTVqYjIwbE1rWnBaRzFoYmpZeU1HSjFhV3hrTWk1bGVHVT0=

http://www.bitsguardtoday.com/WVl6OTRQVFpvVkhneWJVbGxhV1ozVlhNMVYycDFVbEJMZUU0NUpUSkNTRmR1ZVdwSWMyUWxNa1o0VjBSaFMwcGxia0UwSlRORUptTTlXRlYxTTJ4ME4yMWllSHB2TmxZbE1rSlNValEwV2swMGVsWnRUa1o0VUdsTFJYUkZXVzVxWjFoWE5qSWxNa1pvUlVGM2NISjVWVEpFTWtOWk5rOW5la3hCTTNWMk5WQnhZMVZzSlRKQ1duaGxia051VkVWSWNqaDVkVkJNUmxoU2FGZGFibWRXZEROaU1rc3hRMWR3YW1kbmRYRm1Ua3MyVm5WVlEwRmhlbTlRUzBreGNWTW1aRzkzYm14dllXUkJjejFKYm5SbGNtNWxkQ3RFYjNkdWJHOWhaQ3ROWVc1aFoyVnlLelV1TVRGSmJuTjBZV3hzWlhJdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdiV2x5Y205eU1pNXBiblJsY201bGRHUnZkMjVzYjJGa2JXRnVZV2RsY2k1amIyMGxNa1pwWkcxaGJqWXlNR0oxYVd4a01pNWxlR1U9

http://www.conceptsgiftrepository.com/WVl6OTRQWEZHUVhac1NHTmhZeVV5UmpOMk5VNHpKVEpHU1dZemF6RlZWR3BaVEV4QmFIRnVWbXg0Y0dKUmVsUlNjbVJaSlRORUptTTlWbXgwWkd4bkpUSkdja050Y2xaWldXYzJabFZRWlVoWmExazVTamhSYjNBMlJWWkhkVzhsTWtKWmRHRkllSFF5ZGtVeWFVNUJkbVl4TmxSclFUSmthMHhDU1VSek0zWlphRkl6UlUxTFNsbG1kMGsxWVhaTVJVZDRVSFZEUm1GR01YUkdWeVV5UWpKVUpUSkdhbVZVYkRWV09ISkRNR280VTFaNEpUSkNUbEZCYzFkbFFYRTNhVzVaWWxOWk5VMXVVbmxyVmxweE9WaFVTRkpuU1dFeWR5VXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFKYm5SbGNtNWxkQ3RFYjNkdWJHOWhaQ3ROWVc1aFoyVnlLelV1TVRGSmJuTjBZV3hzWlhJdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdiV2x5Y205eU1pNXBiblJsY201bGRHUnZkMjVzYjJGa2JXRnVZV2RsY2k1amIyMGxNa1pwWkcxaGJqWXlNR0oxYVd4a01pNWxlR1U9

http://www.conceptsgiftrepository.com/WVl6OTRQVzFFUmt4RGJsZFhjMDFuZW5kbFJtdFJjVTgwVTJscFJERm9UR1I2T0hVNFZWcEpXVFl3UVZWcU5Va2xNMFFtWXowM2VERXdaSHA2TUhsVE1TVXlRamhtVlZrd2JtTllXazAwYjNkalNteHVUR0Z2U0VkME5FRnFRM1U0YzBNeU1DVXlSblZ1VERJek5XRnJTRTUzVm5rNFRsSmxjMkkxYnpKM0pUSkNRV1ZoZUdjMmRtWlBUVXhEWjJkck0xUnhWMlJGSlRKR2VVRXlNa05LVlVwQ1RHWWxNa0lsTWtKd1drSlhNMjV6VGpGMmJuZE1NbVpxUjNkM2VIUlJkR1I1ZURKVVZXWlFPV1JQV1UxNlZWcDRaRFZpTUhjbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlTVzUwWlhKdVpYUXJSRzkzYm14dllXUXJUV0Z1WVdkbGNpczFMakV4U1c1emRHRnNiR1Z5TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJtMXBjbkp2Y2pJdWFXNTBaWEp1WlhSa2IzZHViRzloWkcxaGJtRm5aWEl1WTI5dEpUSkdhV1J0WVc0Mk1qQmlkV2xzWkRJdVpYaGw=

http://www.conceptsgiftrepository.com/WVl6OTRQVkpNVTBOYU5tNXhXSFo1SlRKQ2NUUWxNa1pwZWpKNU1YZDVVbGxyU1RaWVpXdE9TMEl6VTBadFZuSk9kbmROSlRORUptTTlTVTUwVkRVbE1rSkpKVEpDYjFGSE56bE1TSEJZWkU5Sk1rWmhiMDlrUkRKVldXaFNhbGRVVldaMk5FdHNXU1V5Um1OUFRUbDBWMlF5YTAxM01VSnNkVWRvSlRKR2EwaERTVzF4ZWt0cFJUVjNZM2szT1RWbWJGRlRkM0JpZW1abE1uSkJWV2xaVFZSYVNXWkJSblpXTTNSbVZVNUlhV3B5ZEV4SWJsRndjMGRDZUdGRlYzRTBTR3hZT1ZwVVZXSllibkYxVEdzMWVWTnhKVEpHVkZJMVVTVXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFKYm5SbGNtNWxkQ3RFYjNkdWJHOWhaQ3ROWVc1aFoyVnlLelV1TVRGSmJuTjBZV3hzWlhJdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdiV2x5Y205eU1pNXBiblJsY201bGRHUnZkMjVzYjJGa2JXRnVZV2RsY2k1amIyMGxNa1pwWkcxaGJqWXlNR0oxYVd4a01pNWxlR1U9

http://www.bestcleanshare.com/c?x=1cHKyL0jnhqnYXvV61ntEq6CJmyv DZIlnZOK96AzrY=&c=YYWAdaqTbjqoMJ pzWu mgYY1N4FGUBBetr Kf/1fMwqsiy2G mOaed/feSxpT6vENdpl5eRah3AM3NdtANl5mkw8ZC2ND30TVGruX5cV19zKzFCHe1cls jdH59i0jHglMQGgeB1UnJEGNfNVATmkQbqYY9AjuOg1mGMd7OtUAUK5lVbpXixDJC9Or2/Wgg&e=0&downloadAs=Internet Download Manager 5.11Installer.exe&fallback_url=http://.../idman620build2.exe

Latest 30 of 390 download URLs

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)