jse_install_app-1449041646800.exe

Installer generic

Parsec Media S.L.

The application jse_install_app-1449041646800.exe, “Installer generic Setup ” by Parsec Media S.L has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is also typically executed from the user's temporary directory.
Publisher:
Generic   (signed by Parsec Media S.L.)

Product:
Installer generic

Description:
Installer generic Setup

Version:
3.3.4.3

MD5:
d570dfb6b311306d798aa037a799661e

SHA-1:
4f840786b68c46435cb520122e52d076b0a5b650

SHA-256:
e4bb3267e97807f9f2399fe140c66efc7ef5bc97fdbe3d683c89e37bb1b304f8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/30/2024 10:34:49 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
16.12.29.8

File size:
787 KB (805,936 bytes)

Product version:
2.8.3

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\jse_install_app-1449041646800.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/10/2015 11:31:25 AM

Valid to:
3/10/2016 10:31:25 AM

Subject:
CN=Parsec Media S.L., O=Parsec Media S.L., S=BARCELONA, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E7B0B9AC6719810F13594D385E6107B1

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.8964

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

Remove jse_install_app-1449041646800.exe - Powered by Reason Core Security