install.exe

Gamebox Setup

337 Technology Limited

The application install.exe by 337 Technology Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from asset.337.com.
Publisher:
337 Technology Limited  (signed and verified)

Product:
Gamebox Setup

Description:
Setup

Version:
1.0.19.16989

MD5:
413154fa3d9b791e763fa6bf6d7dcd65

SHA-1:
81cc944b58f33563fb69d24f0e78c82b5625501d

SHA-256:
ff0245f54378afafda2d06d26e0e1a71ba23d827f7e064675192e46ff0585b1f

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/6/2024 2:40:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ELEX.337Technology.Installer (M)
16.1.30.6

File size:
18 MB (18,855,688 bytes)

Product version:
1.0.19.16989

Copyright:
Copyright (c) 2011-2014 337 Technology Limited

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\install.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/25/2012 6:04:18 AM

Valid to:
6/26/2015 6:04:18 AM

Subject:
CN=337 Technology Limited, O=337 Technology Limited, L=香港, S=香港, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A511A565DC1022CCD7BA41E2E418FE65

File PE Metadata
Compilation timestamp:
9/29/2014 8:12:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
393216:9WpFh3C5ASufslK/kKaoX5hkcYMuY9vfd6esO/NBF1gJeaT8Jw:4FVCGSufse3yu96esKnaJeaTmw

Entry address:
0xF944

Entry point:
E8, 9E, 62, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 85, F6, 75, 13, E8, 7A, 27, 00, 00, 6A, 16, 5E, 89, 30, E8, 12, 35, 00, 00, 8B, C6, EB, 24, 68, 80, 00, 00, 00, FF, 75, 10, FF, 75, 0C, E8, 17, 00, 00, 00, 83, C4, 0C, 89, 06, 85, C0, 74, 04, 33, C0, EB, 07, E8, 4A, 27, 00, 00, 8B, 00, 5E, 5D, C3, 6A, 0C, 68, 68, EC, 42, 00, E8, B1, 39, 00, 00, 33, C9, 89, 4D, E4, 33, C0, 8B, 7D, 08, 85, FF, 0F, 95, C0, 85, C0, 75, 17, E8, 21, 27, 00, 00, C7, 00, 16, 00, 00, 00, E8, B8, 34, 00, 00, 33, C0...
 
[+]

Code size:
135.5 KB (138,752 bytes)

The file install.exe has been seen being distributed by the following URL.

Remove install.exe - Powered by Reason Core Security