icreinstall_pype_2.8.8_setup.exe

Internext Media

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_pype_2.8.8_setup.exe by Internext Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Internext Media  (signed and verified)

MD5:
bfeb98eec57a95950f70c17b55a95336

SHA-1:
28e4667d7b69a7ec4bf793f8a83adbad14f7d36e

SHA-256:
4134b231024158178d9afdb05999ce204c73f0173097a7c07d5a41096f80035f

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/17/2024 3:47:37 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore (M)
17.1.29.4

File size:
1.1 MB (1,122,936 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_pype_2.8.8_setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/30/2012 8:00:00 AM

Valid to:
5/31/2013 7:59:59 AM

Subject:
CN=Internext Media, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Internext Media, L=Iasi, S=Iasi, C=RO

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5ECFD6732AA470D2C1BC7F0E7F057C71

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xC98C0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 80, AE, 40, 00, E8, 5E, DA, FF, FF, 4F, 62, 6A, 65, 63, 74, 30, 11, 40, 00, 07, 07, 54, 4F, 62, 6A, 65, 63, 74, 24, 11, 40, 00, 00, 00, 00, 00, 00, 00, 06, 53, 79, 73, 74, 65, 6D, 00, 00, 50, 11, 40, 00, 0F, 0A, 49, 49, 6E, 74, 65, 72, 66, 61, 63, 65, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, C0, 00, 00, 00, 00, 00, 00, 46, 06, 53, 79, 73, 74, 65, 6D, 03, 00, FF, FF, CC, 83, 44, 24, 04, F8, E9, 35, 4E, 00, 00, 83, 44, 24, 04, F8, E9, 53, 4E, 00, 00, 83, 44, 24, 04, F8...
 
[+]

Entropy:
7.0103

Developed / compiled with:
Microsoft Visual C++

Code size:
818 KB (837,632 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_pype_2.8.8_setup.exe - Powered by Reason Core Security