instagram.exe

Lotone

Nummorum

The application instagram.exe, “Lotone Setup ” by Nummorum has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.megagiftcity.com.
Publisher:
Nummorum  (signed and verified)

Product:
Lotone

Description:
Lotone Setup

MD5:
360a2a750d8f45390663241d8d892e6e

SHA-1:
635ada09aa9d5b46b86fc00a9ad6047b3a409ede

SHA-256:
b88bc3ee00f20fc2baf95d7603e5ebbd17a270f9e0e3a0593c36300427aeee1a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
1/13/2025 6:34:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
17.3.11.12

File size:
1.1 MB (1,192,480 bytes)

Product version:
2.7

Copyright:
Application program

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\instagram.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
5/30/2016 8:14:51 AM

Valid to:
5/31/2017 8:14:51 AM

Subject:
CN=Nummorum, O=Nummorum, L=Leusden, C=NL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121EBC3ACFB4E4B6AE7D7966A49416BF44D

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9839

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file instagram.exe has been seen being distributed by the following URL.

http://www.megagiftcity.com/M5Cr XPVSm2E7z8EwbElaT_onzEUvJSip6uPjAWS8bPOA3us Oiog_danP8ATyswgBtFtVDC5CplcrhYYH8p5EkrO7GnUTwcFm 5Z80YnyIgh3fyga8oguzdfSBUgp8GD egLjViS4tI0Mi3fmliUdPC_w274HdLMHNBjhJ8yYhsB4IdD3ws8yOACt0Wp10nXS IaP8O3Z9dBkjAtNLmNgu2EDP1l6aFXl2xNiMrRrIEziY MBmiuIF7eyX28GYps8BTw9oOHqwiOQXBaZeR41sn6whIE8_7t67W7O835GNbw6TLcgo_0U3Pnev5xIjdQeepZL24-Gy8AAERPPS ct0hPNDPZYCIH7LVEDorvqfNA3Xi12ZDSgP_5gTk50iUMG9yl4gM=

Remove instagram.exe - Powered by Reason Core Security