java_runtime_enviroment_setup.exe

Installer

OOO KOD 7

The application java_runtime_enviroment_setup.exe by OOO KOD 7 has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from prepared.softterminal.download. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
OOO KOD 7  (signed and verified)

Product:
Installer

Version:
1.0.0.0

MD5:
322547bd48cef60034fad0a760f2233c

SHA-1:
89d2e4682c6d18c631274e5f3cce3d2353bb8ebf

SHA-256:
e1223ad2302b9c82c2cd170f647340b1b0b6bd30fd704f1611d22aed1205cfd0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 4:20:18 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.OOOKOD7.Installer (M)
16.4.18.9

File size:
788.1 KB (807,040 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\java_runtime_enviroment_setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/4/2015 5:00:00 PM

Valid to:
5/4/2016 4:59:59 PM

Subject:
CN=OOO KOD 7, O=OOO KOD 7, STREET="per. Kotelnicheski 1-i, d. 3 korp. 1", L=Moscow, S=Moscow, PostalCode=109240, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0DA768041E424621AF314DB7899002F9

File PE Metadata
Compilation timestamp:
4/13/2016 1:17:53 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:BiFYkajGcjRod1IzLDjnxqpI1oQ0b7B/yWB:IVaCc9ow/+l

Entry address:
0xC305E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.3827

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
772.5 KB (791,040 bytes)

The file java_runtime_enviroment_setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove java_runtime_enviroment_setup.exe - Powered by Reason Core Security