itunessetup.exe

Monarch Downloads

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application itunessetup.exe by Monarch Downloads has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Adknowledge Fusion installer. With this installer, users are expecting to download Apple's iTunes but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Monarch Downloads  (signed and verified)

MD5:
b9909b9904f1e076a6c3841865d24d51

SHA-1:
40ed9c36ece743cde85da7e84b36cc39868a976f

SHA-256:
01ce5fa3f7a337b2567fb7abb0f72f203ff9000127618ac8f42cc8d5d0ad5767

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/23/2024 10:21:15 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Adknowledge.MonarchD.Bundler (M)
16.7.9.23

File size:
111.8 KB (114,528 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\itunessetup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/23/2014 6:00:00 PM

Valid to:
3/24/2015 5:59:59 PM

Subject:
CN=Monarch Downloads, O=Monarch Downloads, STREET="4600 Madison Ave, 10th FL", L=Kansas City, S=Missouri, PostalCode=64112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6ED4FE307D4F8068EFCDF769A3803C67

File PE Metadata
Compilation timestamp:
5/11/2014 2:04:44 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:N0YBsBE3ain2Q5xq10DZYzIydqyzayMkqq/uzEfk0aQ:WnBTi2CRDZYzIy7za7j2kZQ

Entry address:
0x322E

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 14, C7, 44, 24, 10, D8, A2, 40, 00, 89, 6C, 24, 1C, FF, 15, 34, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, 34, 81, 40, 00, 55, FF, 15, AC, 82, 40, 00, 6A, 08, A3, 58, AF, 47, 00, E8, 9F, 2E, 00, 00, A3, A4, AE, 47, 00, 55, 8D, 44, 24, 34, 68, B4, 02, 00, 00, 50, 55, 68, B8, 01, 44, 00, FF, 15, 7C, 81, 40, 00, 68, C0, A2, 40, 00, 68, A0, 2E, 47, 00, E8, 0A, 2B, 00, 00, FF, 15, 38, 81, 40, 00, BB, 00, B0, 4C, 00, 50, 53, E8, F8, 2A, 00, 00...
 
[+]

Entropy:
4.7093

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file itunessetup.exe has been seen being distributed by the following URL.

Remove itunessetup.exe - Powered by Reason Core Security