installer_microsoft_excel_italian.exe

Free Software LLC

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application installer_microsoft_excel_italian.exe by Free Software has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from scaricaresoft.com.
Publisher:
Free Software LLC  (signed and verified)

MD5:
0f1767f7b307a58bc1e65d16d92254b3

SHA-1:
069868fe53fdd43a1591b961c0f25cd5165c5ea1

SHA-256:
374c1a23dfa41293911b1dd45b3c48689261ad10c047dc1afc07371a31e69ae7

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/23/2024 7:46:10 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Malware-gen
140813-1

AVG
Generic
2015.0.3376

Dr.Web
Trojan.Packed.28459
9.0.1.05190

ESET NOD32
Win32/InstallCore.QJ (variant)
8.10291

F-Prot
W32/InstallCore.AC.gen
v6.4.7.1.166

Malwarebytes
PUP.Optional.Vittalia
v2014.08.21.10

McAfee
Adware-DomaIQ
5600.7032

Reason Heuristics
PUP.FreeSoftware.b
14.8.21.8

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.4782551
32210

File size:
878.6 KB (899,704 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\installer_microsoft_excel_italian.exe

Digital Signature
Authority:
Starfield Technologies, Inc.

Valid from:
8/1/2014 12:08:01 PM

Valid to:
7/22/2015 1:23:49 PM

Subject:
CN=Free Software LLC, O=Free Software LLC, L=Wilmington, S=Delaware, C=US

Issuer:
SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
27DD6AADCC34E6

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:vDjNZuTN5VLR8Bt76jmWaXDVU3hziyZW1+/WNJTv:f3uh5VRwtuYDG3hziy8gkV

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_microsoft_excel_italian.exe has been seen being distributed by the following URL.

Remove installer_microsoft_excel_italian.exe - Powered by Reason Core Security