installer.exe.downloading

The file installer.exe.downloading has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.tourstodayhosting.com and multiple other hosts.
MD5:
58c866fd0c3b980ffc5153780a75852d

SHA-1:
9630973767deb6e7a250ee0c2bc1b460ba8281d5

SHA-256:
f0758db19c8af703326601b4ec008ad8f921752d6681a8c0b09b9a150db9afdc

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/24/2024 7:22:43 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Downloader
2016.02.27

ESET NOD32
Win32/InstallCore.ACY.gen potentially unwanted application
7.0.302.0

Qihoo 360 Security
QVM20.1.Malware.Gen
1.0.0.1120

Reason Heuristics
Adware.Bundler (M)
16.3.7.0

File size:
487.4 KB (499,060 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\installer.exe.downloading

File PE Metadata
Compilation timestamp:
12/27/2015 6:38:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:Fo59uc7vwLOBGW9xiMu7tt1l2a0hOj1SCA:Fo5AziBGWyMuxRH0hmICA

Entry address:
0x310D

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 57, 33, DB, 68, 01, 80, 00, 00, 89, 5C, 24, 1C, C7, 44, 24, 14, 88, 91, 40, 00, 33, F6, C6, 44, 24, 18, 20, FF, 15, B4, 70, 40, 00, FF, 15, B0, 70, 40, 00, 66, 3D, 06, 00, 74, 11, 53, E8, E4, 2D, 00, 00, 3B, C3, 74, 07, 68, 00, 0C, 00, 00, FF, D0, 68, 7C, 91, 40, 00, E8, 65, 2D, 00, 00, 68, 74, 91, 40, 00, E8, 5B, 2D, 00, 00, 68, 68, 91, 40, 00, E8, 51, 2D, 00, 00, 6A, 0D, E8, B4, 2D, 00, 00, 6A, 0B, E8, AD, 2D, 00, 00, A3, 44, EC, 42, 00, FF, 15, 34, 70, 40, 00, 53, FF...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file installer.exe.downloading has been seen being distributed by the following 3 URLs.

Remove installer.exe.downloading - Powered by Reason Core Security