install_sopcast3.2.9.exe

The executable install_sopcast3.2.9.exe has been detected as malware by 19 anti-virus scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source. This version of the installer will bundle the Ask.com Toolbar, a potentially unwanted web browser extension. The file has been seen being downloaded from cdn.instaladores.elpartidodehoy.es.
MD5:
a040fcea4e8998a28a34c81357d6b45f

SHA-1:
c374332e912e59a14f1e8ccd6101c1b7f513126b

SHA-256:
1bb79fd936c66754d9be0ae9274adfcb01a932cc988071dd10b8d624fd35f860

Scanner detections:
19 / 68

Status:
Malware

Explanation:
This is part of the Crossrider Internet browser extension framework which may modify the user's web browser settings including changing the home and search pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
11/27/2024 7:53:03 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.StartPage.@FZ@aGDCosci
494

Avira AntiVirus
TR/Agent.5364595
7.11.120.204

avast!
Win32:Malware-gen
2014.9-150929

Baidu Antivirus
Trojan.Win32.Bundled
4.0.3.15929

Bitdefender
Gen:Trojan.StartPage.@FZ@aGDCosci
1.0.20.1360

Bkav FE
W32.Clodecf.Trojan
1.3.0.4613

Dr.Web
Trojan.StartPage.42573
9.0.1.0272

Emsisoft Anti-Malware
Gen:Trojan.StartPage.@FZ@aGDCosci
8.15.09.29.09

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant)
9.9190

F-Secure
Gen:Trojan.StartPage.@FZ@aGDCosci
11.2015-29-09_3

G Data
Gen:Trojan.StartPage.@FZ@aGDCosci
15.9.22

K7 AntiVirus
Trojan
13.174.10575

Kaspersky
Trojan.Win32.Pasta
14.0.0.1353

McAfee
Artemis!A040FCEA4E89
5600.6628

MicroWorld eScan
Gen:Trojan.StartPage.@FZ@aGDCosci
16.0.0.816

Norman
Suspicious_Gen5.IKBK
11.20150929

Rising Antivirus
PE:Trojan.Dropper!6.3CE
23.00.65.15927

Trend Micro House Call
TROJ_GEN.R0CBH07KJ13
7.2.272

VIPRE Antivirus
Trojan.Win32.Generic
24540

File size:
5.1 MB (5,364,595 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Common path:
C:\users\{user}\downloads\install_sopcast3.2.9.exe

File PE Metadata
Compilation timestamp:
4/14/2011 12:02:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
98304:5PMpbDO36KSB0kpRbQwgUV4iwCLtNKXJ3pNxWzpRP0c6Zg/PcAbN1tBjKk:OFQo0yRGUWiwCLLOOpicacPcAbnjH

Entry address:
0x3834

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, 7C, 01, 00, 00, E8, 5B, 4C, 00, 00, 83, EC, 0C, 68, 01, 80, 00, 00, E8, AE, 45, 00, 00, 6A, 00, E8, 97, 4C, 00, 00, A3, 90, 34, 7A, 00, 6A, 08, E8, 7E, 28, 00, 00, A3, 40, 35, 7A, 00, 8D, 85, 90, FE, FF, FF, 6A, 00, 68, 60, 01, 00, 00, 50, 6A, 00, 68, 50, A2, 40, 00, E8, 4C, 4B, 00, 00, 83, EC, 0C, 68, 51, A2, 40, 00, 68, 70, 35, 7A, 00, E8, 9E, 2A, 00, 00, 83, C4, 18, E8, 72, 45, 00, 00, 52, 52, 50, 68, 00, C0, 7A, 00, E8, 89, 2A, 00, 00, 57, 6A, 00, E8, 3D, 44, 00, 00, 83...
 
[+]

Code size:
29.5 KB (30,208 bytes)

The file install_sopcast3.2.9.exe has been seen being distributed by the following URL.

Remove install_sopcast3.2.9.exe - Powered by Reason Core Security