lanstate-pro-setup.exe

10-Strike LANState Pro

10-Strike Software

The application lanstate-pro-setup.exe, “10-Strike LANState Pro Setup ” by 10-Strike Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.10-strike.com.
Publisher:
10-Strike Software   (signed by 10-Strike Software)

Product:
10-Strike LANState Pro

Description:
10-Strike LANState Pro Setup

MD5:
f59bf98c195d38b36d4b0de697e19a99

SHA-1:
d7578443eb40832b4c1bcd62190c822b2a7751a8

SHA-256:
65922e537065cdc4c400554a662bf9ac92476fa3276113feb259cd7b95985419

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/8/2024 8:08:39 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
17.2.28.5

File size:
19.1 MB (19,975,528 bytes)

Product version:
8.5

Copyright:
(c) 2003-2017 10-Strike Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\lanstate-pro-setup.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
3/16/2016 5:30:00 AM

Valid to:
4/30/2017 5:29:59 AM

Subject:
CN=10-Strike Software, O=10-Strike Software, L=Ulyanovsk, S=Ulyanovsk, C=RU

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0C2D0D2F42480B1FD62F609AA748769D

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xAA98

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 2E, 86, FF, FF, E8, 35, 98, FF, FF, E8, 9C, 9B, FF, FF, E8, B7, 9F, FF, FF, E8, 56, BF, FF, FF, E8, ED, E8, FF, FF, E8, 54, EA, FF, FF, 33, C0, 55, 68, 69, B1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 32, B1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, D0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, C2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, 24, 93, FF, FF, 8D, 55, F0, 33, C0, E8, 66, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9998

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
40.5 KB (41,472 bytes)

The file lanstate-pro-setup.exe has been seen being distributed by the following URL.

http://www.10-strike.com/.../lanstate-pro-setup.exe

Remove lanstate-pro-setup.exe - Powered by Reason Core Security