jdownloadersetup09581.exe

JDownloader

AppWork GmbH

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application jdownloadersetup09581.exe by AppWork GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from ddlp2.data.hu. While running, it connects to the Internet address update1.jdownloader.org on port 80 using the HTTP protocol.
Publisher:
AppWork GmbH  (signed and verified)

Product:
JDownloader

Version:
0.9

MD5:
0fde492b6b6d2eca7398c80c85683ee5

SHA-1:
24e928a3fae6a31adb2b995a28ef768679c688ef

SHA-256:
724984e908fccefc110622c4894307739317e1c6205f67e7c4bbeb9c2f0eed5f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/14/2024 2:51:15 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.AppWorkGmbH.V
14.7.28.0

File size:
24.2 MB (25,399,424 bytes)

Product version:
0.9

Copyright:
AppWork GmbH

Original file name:
jd_windows_0_9.exe

File type:
Executable application (Win64 EXE)

Bundler/Installer:
installCore

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
3/1/2011 11:00:48 AM

Valid to:
3/1/2014 11:00:41 AM

Subject:
E=e-mail@appwork.org, CN=AppWork GmbH, O=AppWork GmbH, L=Fürth, S=Bavaria, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012E71E7355C

File PE Metadata
Compilation timestamp:
4/7/2011 8:35:41 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
393216:a1STZsKViJKMNrFbsxPCVaOYgmRsD88bKVDTnEl6S99HZdW86myfB2tnjL6BVjXU:aEFs5rFbsaaVgasDLmmpNkf3mCvTgCM

Entry address:
0x11F8

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
179.5 KB (183,808 bytes)

The file jdownloadersetup09581.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to update1.jdownloader.org  (178.63.91.110:80)

Remove jdownloadersetup09581.exe - Powered by Reason Core Security