jdsetup130543197880928000.exe

JDownloader2 (BETA)

Appwork GmbH

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application jdsetup130543197880928000.exe, “JDownloader2 (BETA) Setup for Windows” by Appwork GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from installer.jdownloader.org and multiple other hosts. While running, it connects to the Internet address static.18.68.251.148.clients.your-server.de on port 80 using the HTTP protocol.
Publisher:
Appwork GmbH  (signed and verified)

Product:
JDownloader2 (BETA)

Description:
JDownloader2 (BETA) Setup for Windows

Version:
2.0.0.5

MD5:
1b565d6bed32cebd8087bc5228f8b3b4

SHA-1:
bfa372c778d40be998f4ec2cfc77c3fc9d46a34d

SHA-256:
bc657ebd6bf63fe477a808e99b6b6feba7f678a5c2e43f1c085e5f7461c4f4fd

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 6:30:16 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.AppworkGmbH.Z
14.9.4.12

File size:
77.9 KB (79,736 bytes)

Product version:
2.0.0.5

Copyright:
AppWork GmbH

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Nullsoft Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\jdsetup130543197880928000.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/15/2014 2:00:00 AM

Valid to:
8/16/2015 1:59:59 AM

Subject:
CN=Appwork GmbH, O=Appwork GmbH, L=Fürth, S=Bayern, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0091626FD168636EDD78A174E8B75DAC

File PE Metadata
Compilation timestamp:
5/11/2014 10:03:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:3kswQDYrZo5isPqo78fXJz19R9lFBtRThFTae9zihXvBC0AcpL5Lss:UDQkrZoosbIfXJ/7BtNCozy/BCaptLs

Entry address:
0x3217

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 98, 37, 42, 00, E8, AD, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, A0, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, E4, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 57, 2A, 00, 00, FF, 15, B0, 70, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 45, 2A...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file jdsetup130543197880928000.exe has been seen being distributed by the following 50 URLs.

http://installer.jdownloader.org/wb131303444167134725two

http://installer.jdownloader.org/wb131311403176670651two

http://installer.jdownloader.org/wb131286444984503658two

http://installer.jdownloader.org/wb131312240591434688two

http://installer.jdownloader.org/wb131269027690190763two

http://installer.jdownloader.org/wb131279128787014619two

http://installer.jdownloader.org/wb131322087665246117two

http://installer.jdownloader.org/wb131240518365420748two

http://installer.jdownloader.org/wb131308531394046182two

http://installer.jdownloader.org/wb131300050643428983two

http://installer.jdownloader.org/wb131302758320937500two

http://installer.jdownloader.org/wb131270020795915025two

http://installer.jdownloader.org/wb131279628823245032two

http://installer.jdownloader.org/wb131297633564762273two

http://installer.jdownloader.org/wb131280567985396991two

http://installer.jdownloader.org/wb131281086571555211two

http://installer.jdownloader.org/wb131145799596162849two

http://installer.jdownloader.org/wb131304812744407303two

http://installer.jdownloader.org/wb131282545944626981two

http://installer.jdownloader.org/wb131289075176573580two

http://installer.jdownloader.org/wb131323971819280701two

http://installer.jdownloader.org/wb131288196789568756two

http://installer.jdownloader.org/wb131301745353553229two

http://installer.jdownloader.org/wb131283644539543748two

http://installer.jdownloader.org/wb131301040057730000two

http://installer.jdownloader.org/wb131307935423771477two

http://installer.jdownloader.org/wb131291579566084369two

http://installer.jdownloader.org/wb131288137093903404two

http://installer.jdownloader.org/wb131291532555311779two

http://installer.jdownloader.org/wb131282952888839203two

Latest 30 of 45,340 download URLs

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to static.18.68.251.148.clients.your-server.de  (148.251.68.18:80)

TCP (HTTP):
Connects to installer.jdownloader.org  (85.131.130.148:80)

Remove jdsetup130543197880928000.exe - Powered by Reason Core Security