java_update.exe

Soft

GERYON ADS SL.

The application java_update.exe, “Soft Setup ” by GERYON ADS SL has been detected as a potentially unwanted program by 10 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.applicationconecptheart.com and multiple other hosts.
Publisher:
Generic Internet Soft   (signed by GERYON ADS SL.)

Product:
Soft

Description:
Soft Setup

Version:
2.3.1.6

MD5:
9a826135a3b794997b35cc79a3289d55

SHA-1:
928c717aa4f88cb5c4b4b4956db9e459fcb1b043

SHA-256:
980a41e471066215d0bca74b45e0e0b3083711314797d4cd71bd2a189d17769b

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/25/2024 11:54:02 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.2909

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.151130

Dr.Web
Trojan.InstallCore.1027
9.0.1.0334

ESET NOD32
Win32/InstallCore.ACP.gen potentially unwanted (variant)
9.12631

Malwarebytes
v2015.11.30.08

McAfee
Artemis!9A826135A3B7
5600.6565

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
1.0.0.1077

Reason Heuristics
PUP.installCore.GERYONADS.Installer (M)
15.11.30.20

Sophos
Install Core Click run software (PUA)
4.98

VIPRE Antivirus
InstallCore
45452

File size:
937.5 KB (959,992 bytes)

Product version:
4.3

Copyright:
Internet Installer

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\java_update.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/23/2015 8:17:17 AM

Valid to:
6/23/2016 8:17:17 AM

Subject:
CN=GERYON ADS SL., O=GERYON ADS SL., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121876A81F90DA17EC052D9EF4E5C681DCD

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:xjMlGpdla+o86+6lEwsQLjX1TVrcLK6deuAM8uPtwfd:xQmTDo86+GFsQ12LKKy

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file java_update.exe has been seen being distributed by the following 9 URLs.

http://www.applicationconecptheart.com/c?x=oo EfMzTtQd0/yhteJvMpTMUqN/8j54PjmmgbEEXXgE=&c=PDbIr2vhkICMVzcVLNuRmZqVcROvBWPfWaEu93ZnvLF0x7NucE bybDrkQUYhogEXfP7/Nal6PjNhoKn7wS870sBd269fAfpuFrXAKXglJGSHKsMcqUkm6vMeENqOzCpxYODUMI3u22SqCvJKT4Peg==&downloadAs=Java_Update.exe&fallback_url=http://javadl.sun.com/webapps/.../AutoDL?BundleId=94214

http://www.factoryupdateflash.com/c?x=66XjGDSpDtJwH4FC 7DKS66i2X2vqLtRaEOiljFVe8o=&c=EZhFuEYzDth E4CfzYLRF/8/tjxQAY6/ Kt23Vlqpa4pA4vpnAyqZ1fMLX0FbT8ld20rHFac AWwKEgYrTQdH8c1Xl6QS8n2Ltb6vj2KJZ9A3AKRWBQ6l5Ng3Hw6MN3fJUArHpXjEs1nR7W1sPHFBA==&downloadAs=Java_Update.exe&fallback_url=http://javadl.sun.com/webapps/.../AutoDL?BundleId=94214

http://www.downloadfuntown.com/c?x=9UJDXfboQ2MHv5qrdul8zWtwZRS1sMXm2zgTZQ2qexM=&c=d9MfEIEc2VGmQQpmP7AdWVAHQIh/WmzL8WxsxeYbs6yncek2aoOrxYZWFTMU8dGj5PxLGzH1nyLhfAdAwDXpdVFMOeICw3CtcApq67hUijj9zgfF90fG7BDBSwDs8QWwExxP9VYgks4LFEbpLV RGQ==&downloadAs=Java_Update.exe&fallback_url=http://javadl.sun.com/webapps/.../AutoDL?BundleId=94214

Remove java_update.exe - Powered by Reason Core Security