icreinstall_malavida_download_manager.exe

Installer Application

Born To Be Net Consulting S.L.

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_malavida_download_manager.exe, “Installer Application Setup ” by Born To Be Net Consulting S.L has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn.puresoftwarebar.com and multiple other hosts. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Web Application   (signed by Born To Be Net Consulting S.L.)

Product:
Installer Application

Description:
Installer Application Setup

Version:
5.8.5.1

MD5:
5694c5ffa7a9a1900b5c8daa94f95271

SHA-1:
2690a585fe088e2121128b6553e1afa66a3934aa

SHA-256:
878f973ae204e08605ba1ad82ba4d1391264e72a2834bcbb8df1d88b2125d9a4

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/15/2024 10:49:34 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.BornToBeNetConsulting.Installer (M)
16.2.24.2

File size:
719.3 KB (736,552 bytes)

Product version:
3.6

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_malavida_download_manager.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/3/2015 2:17:26 PM

Valid to:
3/3/2016 2:17:26 PM

Subject:
CN=Born To Be Net Consulting S.L., O=Born To Be Net Consulting S.L., L=Valencia, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D8D6D0E6657B5210B0CE2D4573FDF9F0

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:H+4uaC6k5eJ7gZfJNSWZWIl+SrWCABbhRov6DPAcvd4jADQyAe2xhCkGH87PP:H+4unxkJQfzXWTSb8bX0uXCjJy32s87n

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file icreinstall_malavida_download_manager.exe has been seen being distributed by the following 3 URLs.

http://cdn.puresoftwarebar.com/c?x=sQz/VmVmyS ljbSbF/K0 cfhq6xbnHGUzK6myz1sVko=&c=KNnMRr2CwN IR9 6Yc1bYI8cB6VwFrp/.../BPPfU1LPPhD5tbiiT1387wp&downloadAs=Malavida_Download_Manager.exe

http://cdn.directapplicationsfloor.com/c?x=ysAPuPL6rm zeJg3M4Rup3NKC9SG3bLA7yHONDSQ/.../ND7P43n uNQrq7aeIjgud6NCPzpoXBC60XwSwBbmXsB&downloadAs=Malavida_Download_Manager.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_malavida_download_manager.exe - Powered by Reason Core Security