icreinstall_plants-vs-zombies-2-4.7.1.exe

Cagolig

Destiny Dream S.A.

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_plants-vs-zombies-2-4.7.1.exe, “Cagolig Setup ” by Destiny Dream S.A has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.tagsendheart.com and multiple other hosts. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Huful   (signed by Destiny Dream S.A.)

Product:
Cagolig

Description:
Cagolig Setup

Version:
3.6.3.0

MD5:
61b72ef1adde14a9f52c8764416e043f

SHA-1:
eb6ad69d41f84642913e852606949c64254c1add

SHA-256:
ea1589743f3bd10aecbf5a92edcb994be046d08ea22e9107fc07f93d68179186

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/27/2024 1:51:33 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.DestinyD.Installer (M)
16.4.26.19

File size:
989.7 KB (1,013,448 bytes)

Product version:
2.0

Copyright:
program

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_plants-vs-zombies-2-4.7.1.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 8:55:11 AM

Valid to:
10/2/2016 9:36:18 AM

Subject:
CN=Destiny Dream S.A., O=Destiny Dream S.A., L=Clarens, S=Vaud, C=CH

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11217A75EB912AE2167326222C18D9E2357F

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:oo9v/Sb8ISdMPNf/kLkfz8HF2+7jDBVCyP39KvlDVJx:o6SkaPNXkQfziF2sjL8l/x

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9262

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file icreinstall_plants-vs-zombies-2-4.7.1.exe has been seen being distributed by the following 48 URLs.

http://www.tagsendheart.com/c?x=ccpfiQAa3X0hZtT7cx30f0KcDjOa T1aRVhekg5WKTA=&c=1MSCEzSRB3Hrz1eZIIHmLnngsCRXkFbKr3gD92DFsoM6mu0/cbcmm5qC0fkN47XmgPAKTtb4Z5 Q6SZ ZuJmyIGbV67qy0skBwMOqcIgz1EFrA5x1ZT5K OSpDK035J7UC7Tn6qiqdHCNKlfC2NNf0kJyeB0RLq iiFRPbyb2ginSBk7BE2C3QsBrWhqCA2b&e=0&downloadAs=plants-vs-zombies-2-4.7.1.exe&fallback_url=https://itunes.apple.com/app/.../id597986893?mt=8

http://www.factorybulknew.com/c?x= vlQtmg28H31i8aUErNrjl593w7Izgy6CdrcyUPa8tQ=&c=h2mcCVlWcRYfQupaJIfTiHnE4vZ6FdUZdQLjlqw7zhv6O6aeA7hsBmyA5BAtw0PCnNVkU/rG77twpf9zM75gAkx6No4VeUMvSA2OGQSEanzvQx8Po8fHoKYbzzX0/5iYJqGNPlyx hWMctRT8BkhJ/vN5oVhSnBXKGrG/NGQy1tG8EJt0VwZgTFpO9IbgwRl&e=0&downloadAs=plants-vs-zombies-2-4.7.1.exe&fallback_url=https://itunes.apple.com/app/.../id597986893?mt=8

http://www.cleansignsconecpt.com/c?x=gCxO3zu9dGdrm0nwC2hi/iZ97kCGJnWLl4oJ6npqHP4=&c=LV6FazxtZ5eGvwLOsOd4kn1ezU/1jl6mF0u7dK 98A9Cq9DV//F3XE8nqpQUtRFCQMiB3vzNvj8vstxfP iJ/osQ5oXyPcFhS0XZ2T0KmDWsDHRreKdnkn56Dclz20MBT/gHRn5MMXDWD i1wJYdDD0Wep183ieLR5BplYnVQcY=&e=0&downloadAs=plants-vs-zombies-2-4.7.1.exe&fallback_url=https://itunes.apple.com/app/.../id597986893?mt=8

http://www.gifttowndelivery.com/WVl6OTRQV056Vm1GM1RsRlVabmsxSlRKR2Fua2xNa1pFUWlVeVFqVTBWaVV5UWpaMmNHUWxNa0pqVm5OaGRWaDNRMmgyVWs5Uk1tMVZKVE5FSm1NOVdGWTBkRWx2VGpoa1ZYYzFTeVV5UmxrM1JVVTVSVFoxY0cweVFXWXlSWFE1YlRCUWNIRkxNQ1V5UWpCSmFrRk1WRXhuUW1GUVVrSlRKVEpHUjBnd1VYSllUblJCUlZobGNXUm9NMW96T1ZGR1pqSndOVXhYVnlVeVJtUm9kRmh0TW13d2RqQjVkSE5LSlRKR05uQkZhbTVHUTBVeVlXVldWVU5CWjJNNVZuUjBZbU5RYVZwclVVTndSMUJ3YUdkMWJHbFJTM1JMYVRKcFREWk9OVkExWnlVelJDVXpSQ1psUFRBbVpHOTNibXh2WVdSQmN6MXdiR0Z1ZEhNdGRuTXRlbTl0WW1sbGN5MHlMVFF1Tnk0eExtVjRaU1ptWVd4c1ltRmphMTkxY213OWFIUjBjSE1sTTBFbE1rWWxNa1pwZEhWdVpYTXVZWEJ3YkdVdVkyOXRKVEpHWVhCd0pUSkdjR3hoYm5SekxYWnpMaTE2YjIxaWFXVnpMVElsTWtacFpEVTVOems0TmpnNU15VXpSbTEwSlRORU9BPT0=

http://www.newgiftcontent.com/c?x=Lbr3EwZsQHAvgVD3XSk49TjAzM3RGb0BFgY5m8 UTpE=&c=jOm2RvKev6lj6Ow7BiggmRyIC5gsBRTk3Dr F3dgg0uXn/GmWoax8bzew1/k/LD1ShsRy2Gxoh97EoA2tBkMPQSa73d0ZxMnu/F2pn2ikeXdaNjo/CxTUOdd/4I6IweehlAslIBpADa3PjXXTcffxw==&e=0&downloadAs=plants-vs-zombies-2-4.7.1.exe&fallback_url=https://itunes.apple.com/app/.../id597986893?mt=8

http://www.cleansignsconecpt.com/c?x=zJ/bv2Q6toxL9e3LWG4RC0nZyS866flG6FmGpII 5Ew=&c=ofTTGH2sxxo8Yl62HPaSPcgAOlMT/UnXoKgVt0NYRFXF/jHsCLIvpdBZI 4brX9qpEY/Nf314 Uwmywne3VM571MwFtZ MtQRzcV2pFqdavNzpBDLJ2Dtqbw1cZyM84qdNEfHfGwUqasOcxsnOJALUDtCASyBS8xXWnh4R dOSc=&e=0&downloadAs=plants-vs-zombies-2-4.7.1.exe&fallback_url=https://itunes.apple.com/app/.../id597986893?mt=8

http://www.presentfuntowers.com/WVl6OTRQWGx6ZEhOR1pVczJRbXhJVXlVeVJuVkNWVTVpZUhGVVMyUkdNRVEzY1V0ek0wcDRlWHBYYVVzMU56Z2xNa1l3SlRORUptTTlTV3hTUVV0TmVEYzRVblo0VWsxVWVqQllibGxpYUdKcVdsRlBOWHBtYTFac2RHUndiU1V5UWxkT2VUbFpkVTB4U213eWRteHZjM2RwVmpacFVFbExaRVpsWkhRbE1rSTRaWFp0VDNwU1p5VXlSbTV3U2paQ1kyRkpRMmxHVmtGR1MweDRhams0ZWxoeGJURlRSVUY1U1dNMFRuZFRWakUxVTAxWE5VcGtjMmx4YUNVeVJsQTJjbTQ1VjNWYVoyeHJiekI1YmtveVRXUnlkalV6WW1jbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTljR3hoYm5SekxYWnpMWHB2YldKcFpYTXRNaTAwTGpjdU1TNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEJ6SlROQkpUSkdKVEpHYVhSMWJtVnpMbUZ3Y0d4bExtTnZiU1V5Um1Gd2NDVXlSbkJzWVc1MGN5MTJjeTR0ZW05dFltbGxjeTB5SlRKR2FXUTFPVGM1T0RZNE9UTWxNMFp0ZENVelJEZz0=

http://www.bundlesbinariesnew.com/c?x=b9vXDR9Ya1G6yr7aHNmURWfsTKRLkfBm6Ge2ws3ElYA=&c=eJlTPEPGkwCgkmxbYzhj6mlrjzEuGshHTBm4HQ5AJCgyBFcbQcucmm7o63nhWr3/BwWhFQIjBXHw7uTgzucJOsVHPore96onhgj4 SZFCq2sh/Uf8orxaG/HhPfY8exDjm4WQ/zbKtDqjofc4BXavw==&e=0&downloadAs=plants-vs-zombies-2-4.7.1.exe&fallback_url=https://itunes.apple.com/app/.../id597986893?mt=8

Latest 30 of 48 download URLs

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_plants-vs-zombies-2-4.7.1.exe - Powered by Reason Core Security