icreinstall_skypesetupfull.exe

App Internet

ELECTRONIC COMMERCE FACTORY, S.L.

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_skypesetupfull.exe, “App Internet Setup ” by ELECTRONIC COMMERCE FACTORY, S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Installer   (signed by ELECTRONIC COMMERCE FACTORY, S.L.)

Product:
App Internet

Description:
App Internet Setup

MD5:
9ff1a8b8f19949048d75f7c67cf8111e

SHA-1:
7490201f4cb2f9efd8d0cbfceafaa9409e425e73

SHA-256:
895b2e01a22b2b134cce06f565c09f62cff25d5195d74ad1a1d0e86dd22cd4c5

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 5:40:18 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore (M)
16.12.4.2

File size:
677 KB (693,280 bytes)

Product version:
2.0

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_skypesetupfull.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
8/5/2014 2:00:00 AM

Valid to:
8/6/2015 1:59:59 AM

Subject:
CN="ELECTRONIC COMMERCE FACTORY, S.L.", OU=IT, O="ELECTRONIC COMMERCE FACTORY, S.L.", L=CASTELLON DE LA PLANA, S=CASTELLON, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
54C2423D8C2DFF66B2FDCD2A0EA98503

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:mrmGlUVLZNKr4ScCd2SmGb3mEv7HrQkGA3F4ErARE0QJ+ysK:mrmwUVLZIESlXmGb3vzH7GA14ErAeVDz

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_skypesetupfull.exe - Powered by Reason Core Security