icreinstall_mp3rocket_setup.exe

Gaki

MP3 TechSupport LLC

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_mp3rocket_setup.exe, “Gaki Setup ” by MP3 TechSupport has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.hostflashconcepts.com and multiple other hosts. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
MP3 TechSupport LLC  (signed and verified)

Product:
Gaki

Description:
Gaki Setup

MD5:
89fd8ee5dbef6f353323b534c2621bae

SHA-1:
17917e3d3930a5a8e5a4a54bb6ee579ac8e94b39

SHA-256:
1ae160d2f48b72611f077443f411a04639c1e6842a62d2f32db894136ff98bc4

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 1:32:55 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore (M)
17.2.15.7

File size:
1.4 MB (1,421,832 bytes)

Product version:
1.8.6

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_mp3rocket_setup.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
1/29/2017 10:00:00 PM

Valid to:
4/21/2018 8:59:59 PM

Subject:
CN=MP3 TechSupport LLC, O=MP3 TechSupport LLC, L=Lehi, S=Utah, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
5ADACEC02DE27C8BEEF159CC436D4A35

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file icreinstall_mp3rocket_setup.exe has been seen being distributed by the following 2 URLs.

http://www.hostflashconcepts.com/jgN_zsXCMQl5ScP G WZmyHpd_bXhQz321QY1kWz3UF3NF9rKUnyyh3jylllK2AlDH Y2OYVTgWQJVmyO6aQy6dV59Kc8ffe p0R42AGs9oi37KeCh7dDAAkgtIoZWwrPhDj1jjRd61clAKOEvIVTTWu083ccg==-Gy8AAATqZLG9ICbhNJvtBeCQA_a3IsnCYGPsXNFGfmPGr6spU1DQc8ym53HiAQ==

http://www.hostflashconcepts.com/Qq4T3EOqWnArf2jejdqIzlqfF9OdN_skqWgu42XuGnEzfGtkUh9fO2nyLkI1oAAH2Dy7IVzIpSNj7yJ0rMlhwGtnTsX_CMrvg1mWvmft1hNJACg3avr7VB06KbO98AC_NPUf3X_ZVcbgq3S464rLEmCycjZd2g==-Gy8AAATqZLG9ICbhNJvtBeCQA_a3IsnCYGPsXNFGfmPGr6spU1DQc8ym53HiAQ==

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_mp3rocket_setup.exe - Powered by Reason Core Security