installer.exe

Veristaff. Com Ltd

The application installer.exe by Veristaff. Com has been detected as adware by 8 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from gogeneral.blob.core.windows.net.
Publisher:
Veristaff. Com Ltd  (signed and verified)

MD5:
a1adc6f31ff0773e6934e876c32fef02

SHA-1:
b822629779692112a64e8c9c2d372ba4b1259fdd

SHA-256:
c7af3232816400a97cc7f5a2fa57851f7bc3ef5c24f5e6ff74e31d8e68faf493

Scanner detections:
8 / 68

Status:
Adware

Analysis date:
11/27/2024 2:15:42 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.W32.Inject
2.1.4+

avast!
Win32:Malware-gen
2014.9-141102

AVG
Trojan horse Dropper.Agent
2015.0.3303

Baidu Antivirus
Trojan.Win32.MsiDrop
4.0.3.14112

ESET NOD32
Win32/TrojanDropper.MsiDrop (variant)
8.10647

IKARUS anti.virus
AdWare.Smartbar
t3scan.1.8.3.0

Reason Heuristics
PUP.VeristaffCom.J
14.8.25.1

Zillya! Antivirus
Dropper.MsiDrop.Win32.1
2.0.0.1973

File size:
9.7 MB (10,196,088 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\installer.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/14/2014 10:37:25 AM

Valid to:
7/15/2015 10:37:25 AM

Subject:
CN=Veristaff. Com Ltd, O=Veristaff. Com Ltd, L=Herzliya, S=Herzliya, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121327C47596D5E76D675A39A539249C1B5

File PE Metadata
Compilation timestamp:
8/13/2014 11:59:14 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:glVSgZ4pasEgSlgdh+Qqo8B08R6A0J4NAe/J6GBul:45SppEgSlErqpCWNAaJ6GEl

Entry address:
0xB01F

Entry point:
E8, 92, 5E, 00, 00, E9, 95, FE, FF, FF, FF, 35, 80, 21, 42, 4F, FF, 15, 88, 90, 41, 4F, 85, C0, 74, 02, FF, D0, 6A, 19, E8, 77, 3E, 00, 00, 6A, 01, 6A, 00, E8, 70, 2E, 00, 00, 83, C4, 0C, E9, 35, 2E, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83...
 
[+]

Code size:
95 KB (97,280 bytes)

The file installer.exe has been seen being distributed by the following URL.

Remove installer.exe - Powered by Reason Core Security