installation.exe

Installation

The application installation.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.ddlmedia1012.info.
Product:
Installation

Version:
1.9.3.0

MD5:
1a4c039d366a2577c4aaa4b644b9c551

SHA-1:
b9bfcd34afb90c79397c901a87074747e546ad0c

SHA-256:
1d1de340191810e0b6a924212a51756af094f28909f4b34f17b420fabcc12279

Scanner detections:
21 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/23/2024 2:25:44 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Outbrowse.4
5774621

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
PUA/Softpulse.Gen
3.6.1.96

avast!
PUP-gen [PUP]
150319-1

AVG
Potentially harmful program Downloader.DQD
2014.0.4311

Bitdefender
Application.Bundler.Outbrowse.BA
1.0.20.590

Dr.Web
infected with Trojan.OutBrowse.109
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.Outbrowse.BA
9.0.0.4799

ESET NOD32
Win32/OutBrowse.BU potentially unwanted
9.11546

Fortinet FortiGate
Riskware/OutBrowse
4/28/2015

F-Secure
Gen:Variant.Application.Bundler
11.2015-28-04_3

G Data
Application.Bundler.Outbrowse.BA
15.4.25

McAfee
Program.Adware-OutBrowse.e
16.8.708.2

MicroWorld eScan
Application.Bundler.Outbrowse.BA
16.0.0.354

NANO AntiVirus
Riskware.Win32.OutBrowse.doqogj
0.30.24.1357

Quick Heal
Adware.NSIS.OutBrowse.A
4.15.14.00

Sophos
Generic PUA LD
4.98

Trend Micro House Call
TROJ_GE.E8AA5DC1
7.2.118

Trend Micro
TROJ_GE.E8AA5DC1
10.465.28

Vba32 AntiVirus
AdWare.OutBrowse
3.12.26.3

VIPRE Antivirus
Threat.5085447
39486

File size:
1.1 MB (1,124,397 bytes)

Product version:
1.9.3.0

Copyright:
Installation

Original file name:
Ionic.Zip-2015Feb22-215921-172cb947-8da1-4971-9dcc-9124aadd6cec.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\installation.exe

File PE Metadata
Compilation timestamp:
2/22/2015 9:59:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:eMiy4IadS4ms5I6e66fEheKh+sgctLILpW17esfQ7Xt+RRLMbPb+1BMqx/T/jL2M:ebSaE4mvt/zsJ2M4oQ7XtYz7r+M/Fhf

Entry address:
0x7604E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5925

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464.5 KB (475,648 bytes)

The file installation.exe has been seen being distributed by the following URL.

Remove installation.exe - Powered by Reason Core Security