icreinstall_via-envy24-audio-controller-family-5-40a-sound-card_setup.exe

Internext Media

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_via-envy24-audio-controller-family-5-40a-sound-card_setup.exe by Internext Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Internext Media  (signed and verified)

MD5:
efb37fbce2ea596d50a7f5bdcd3644a2

SHA-1:
d6f2b5ad9fdb8ffab1a65d5e2bbdf3394a74dd90

SHA-256:
5340e2098c8565bd742610b51d6898675c4f40eaea38ab86c4112b24995de466

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/17/2024 3:32:05 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore (M)
17.3.12.16

File size:
1 MB (1,087,096 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_via-envy24-audio-controller-family-5-40a-sound-card_setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/29/2012 9:00:00 PM

Valid to:
5/30/2013 8:59:59 PM

Subject:
CN=Internext Media, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Internext Media, L=Iasi, S=Iasi, C=RO

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5ECFD6732AA470D2C1BC7F0E7F057C71

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xC1ADC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 28, 1A, 41, 00, E8, 3F, E6, FF, FF, 00, 00, 00, 00, E8, 10, 40, 00, 04, 00, 00, 00, 00, 00, 00, 00, D4, 36, 40, 00, E0, 36, 40, 00, E4, 36, 40, 00, E8, 36, 40, 00, DC, 36, 40, 00, 3C, 34, 40, 00, 58, 34, 40, 00, 94, 34, 40, 00, 07, 54, 4F, 62, 6A, 65, 63, 74, F4, 10, 40, 00, 07, 07, 54, 4F, 62, 6A, 65, 63, 74, E8, 10, 40, 00, 00, 00, 00, 00, 00, 00, 06, 53, 79, 73, 74, 65, 6D, 00, 00, 14, 11, 40, 00, 0F, 0A, 49, 49, 6E, 74, 65, 72, 66, 61, 63, 65, 00, 00, 00, 00, 01, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
788 KB (806,912 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)