iTunes Setup.exe

Internet

Silver Setup (Fried Cookie Ltd.)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application iTunes Setup.exe, “Internet Setup ” by Silver Setup (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. With this installer, users are expecting to download Apple's iTunes but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Silver Setup (Fried Cookie Ltd.)  (signed and verified)

Product:
Internet

Description:
Internet Setup

Version:
1.2.3.8

MD5:
bb08fe37785e15258aa96a1c63b9d6ca

SHA-1:
8493b5414a0b8adb0ee0ef722dc6507542828403

SHA-256:
8e7ed8bb83f6b29a0d14d2ef2ed5cf06e05cc54d68e37f38abffa1d2d56904bd

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/28/2024 2:32:13 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.Installer.Installer (M)
16.2.4.18

File size:
963.4 KB (986,472 bytes)

Product version:
3.3

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\itunes setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 11:13:58 AM

Valid to:
7/24/2016 11:33:54 AM

Subject:
CN=Silver Setup (Fried Cookie Ltd.), O=Silver Setup (Fried Cookie Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112140334915ED026A82D6160FD4F0BAD4D4

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:uevQdNB1+F3tA5IWFJVxYRDRGkvUM0R/JZNs3:uRPB1+dtAJYRDRrvBC/JZw

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file iTunes Setup.exe has been seen being distributed by the following 42 URLs.

http://www.hostheadflash.com/c?x=QlyM3YeNbbFnxAwxQltKsXSaoXRP1BnSIpedW0CS/Dg=&c=Ss0RZRD3nDItEuZKlTuoDO7BJ2F5yHt9Pjd8rRYoSmsLYmUzB0/YNs5koQ/.../SUTeLSx4EBnhs6d9&downloadAs=iTunes Setup.exe

http://www.bundlesbytetown.com/c?x=XQFvvcG8swv7usAdHCnSs cSdfa wgDkKL9j uWVgrw=&c=qYSYhubVTBDJN5rrv1qS2GtQ8VY6aH1 GL69aKCdLhUWfD82CC7ebQTKqmDQP3Fpv9gsN7UCIUM nAn1AU9DLDDFBCAMfn/6Z9Ujj6/.../8JyBfTI21PuLlaq2M&downloadAs=iTunes Setup.exe

Latest 30 of 42 download URLs

Remove iTunes Setup.exe - Powered by Reason Core Security