installer.exe

Kreapixel Network

The application installer.exe by Kreapixel Network has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from softs.illyx.com.
Publisher:
Kreapixel Network  (signed and verified)

Description:
xcvxcv

Version:
3.0.0.27

MD5:
5b1ef872113e89e6672a76d7376c6ee6

SHA-1:
eef68c5791ce4bf9d2968f29ef31b7524b310962

SHA-256:
20d1e82f040f20be982ef18bde1f48c8b1b32050f8dbc9170528dc4c9e4935f5

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 1:59:39 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Kreapixel.Installer (M)
16.5.2.10

File size:
1.1 MB (1,136,480 bytes)

Product version:
3.3.10.2

Copyright:
xcvsdf

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\installer.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/27/2014 2:00:00 AM

Valid to:
6/27/2015 1:59:59 AM

Subject:
CN=Kreapixel Network, OU=24, O=Kreapixel Network, L=Bergerac, S=Dordogne, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
08C337D1809F41539363BCF60D881AB2

File PE Metadata
Compilation timestamp:
7/31/2014 6:10:29 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:W4lavt0LkLL9IMixoEgeaLhmn2v8qPA0PVq9MmCSm:hkwkn9IMHeaFmn2v8qY0taPCSm

Entry address:
0x26BF7

Entry point:
E8, 97, CF, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 58, 01, 4C, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 70, A3, 4B, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 58, 01, 4C, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03...
 
[+]

Code size:
560 KB (573,440 bytes)

The file installer.exe has been seen being distributed by the following URL.

Remove installer.exe - Powered by Reason Core Security