jzipsetup-r3-n-bi.exe

jZip

Bandoo Media, Inc.

The application jzipsetup-r3-n-bi.exe by Bandoo Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from download.cdn.jzip.com.
Publisher:
Bandoo Media Inc  (signed by Bandoo Media, Inc.)

Product:
jZip

Description:
jZip Install

Version:
2.0.0.135670

MD5:
0cf29a39c22367adc88e013f7465abc8

SHA-1:
d91e4ebb1c4d84799e80e7ab0efefdb95b6d440e

SHA-256:
222d9f929a54b2db9352cd5a3b035fef300c739b1d867544fb2acf962900430a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
May bundle additional software offers in the setup installer included a branded Ask.com Toolbar (Movies/Music Toolbar).

Analysis date:
12/26/2024 4:31:53 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bandoo.BandooMe.Installer (M)
16.4.21.13

File size:
1.4 MB (1,417,568 bytes)

Product version:
2.0.0.135670

Copyright:
Copyright (c) 2015 Bandoo Media Inc

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\jzipsetup-r3-n-bi.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
9/16/2015 5:00:00 PM

Valid to:
2/23/2016 3:59:59 PM

Subject:
CN="Bandoo Media, Inc.", O="Bandoo Media, Inc.", L=Panama City, S=Panama, C=PA

Issuer:
CN=thawte SHA256 Code Signing CA - G2, O="thawte, Inc.", C=US

Serial number:
0AEA776A90BF58BA2DEB5770F39F9A26

File PE Metadata
Compilation timestamp:
2/24/2012 11:20:04 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:JOKqnV3CutER7v4HvAvc+YJJIMZqHorkMBXDf7cGERFeP12mGA:e3C/WYyKMZOwXDfYGqFUG

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 84, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 18, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Entropy:
7.9636

Packer / compiler:
Nullsoft install system v2.x

Code size:
29 KB (29,696 bytes)

The file jzipsetup-r3-n-bi.exe has been seen being distributed by the following URL.

Remove jzipsetup-r3-n-bi.exe - Powered by Reason Core Security