install_jd_two.exe

Appwork GmbH

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application install_jd_two.exe by Appwork GmbH has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from r2.computerbild.de and multiple other hosts. While running, it connects to the Internet address installer.jdownloader.org on port 80 using the HTTP protocol.
Publisher:
Appwork GmbH  (signed and verified)

MD5:
61a456ede0f1e9de9a4de332eb1a8ab1

SHA-1:
b3412886d10c4c352453aaa4a6d96757174cf18d

Scanner detections:
2 / 68

Status:
Potentially unwanted

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
2/25/2025 5:50:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.AppworkGmbH
15.1.25.8

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

File size:
226.1 KB (231,544 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Nullsoft Install System)

Common path:
C:\documents and settings\owner\デスクトップ\install_jd_two.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/15/2014 9:00:00 AM

Valid to:
8/16/2015 8:59:59 AM

Subject:
CN=Appwork GmbH, O=Appwork GmbH, L=Fürth, S=Bayern, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0091626FD168636EDD78A174E8B75DAC

File PE Metadata
Compilation timestamp:
5/12/2014 5:03:42 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:04SUjht47NvyrGrDFmd5poaXme0mp5B6Ay3X53gx5C/Yv:7QEd5po9BmD4Ay32xA/2

Entry address:
0x30E2

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 58, E4, 42, 00, E8, 95, 2D, 00, 00, A3, A4, E3, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, E0, 87, 42, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, A0, DB, 42, 00, E8, 3F, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 40, 43, 00, 50, 55, E8, 2D, 2A...
 
[+]

Entropy:
7.3736

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file install_jd_two.exe has been seen being distributed by the following 10 URLs.

http://r2.computerbild.de/exec/r2r.pl?m=w-cobi;u=http://d.computerbild.de/downloads/.../Install_JDownloader_2_BETA.exe

http://fetch.jdcdn.org/7939558741356264638.php?l=3&t=1425424871&v=2&e=1425424876&s=PST_gaS4bHn19ThL7juRYEmWY7k

http://pf.dlvit.com/s/.../2/228763-671313-jdownloader-2.exe

http://78.140.184.180/d/.../SupportJDownloader.exe

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to installer.jdownloader.org  (85.131.130.148:80)

Remove install_jd_two.exe - Powered by Reason Core Security