launcher_i386495491.exe

Installer

The executable launcher_i386495491.exe has been detected as malware by 1 anti-virus scanner. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.extractdownload.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Product:
Installer

Version:
1.1.2.41

MD5:
53d83e1ee7c2c091c5ea6ef68c8bc835

SHA-1:
922889a54a2756a252dfd6a5fdee650d3c3cd5de

SHA-256:
754590151e219623097b62defaa3b6124a232c6639cc51438386ac67702b8872

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/27/2024 5:26:34 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.1.10.7

File size:
322.5 KB (330,240 bytes)

Product version:
2.1.12

Copyright:
Copyright(c), All Rights Reserved.

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\launcher_i386495491.exe

File PE Metadata
Compilation timestamp:
2/25/2014 10:39:03 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:a3oNfdLHweH5SfQurZBBXPfaNVFOe7E9kFXeVJUZFZ8fSF634yPNX0upc9lU:a3oNfdrweHUfQurxXPf562cF+fSF634Z

Entry address:
0x26EA4

Entry point:
E8, BC, 95, 00, 00, E9, 89, FE, FF, FF, 57, 8B, C6, 83, E0, 0F, 85, C0, 0F, 85, C1, 00, 00, 00, 8B, D1, 83, E1, 7F, C1, EA, 07, 74, 65, EB, 06, 8D, 9B, 00, 00, 00, 00, 66, 0F, 6F, 06, 66, 0F, 6F, 4E, 10, 66, 0F, 6F, 56, 20, 66, 0F, 6F, 5E, 30, 66, 0F, 7F, 07, 66, 0F, 7F, 4F, 10, 66, 0F, 7F, 57, 20, 66, 0F, 7F, 5F, 30, 66, 0F, 6F, 66, 40, 66, 0F, 6F, 6E, 50, 66, 0F, 6F, 76, 60, 66, 0F, 6F, 7E, 70, 66, 0F, 7F, 67, 40, 66, 0F, 7F, 6F, 50, 66, 0F, 7F, 77, 60, 66, 0F, 7F, 7F, 70, 8D, B6, 80, 00, 00, 00, 8D, BF...
 
[+]

Code size:
228.5 KB (233,984 bytes)

The file launcher_i386495491.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove launcher_i386495491.exe - Powered by Reason Core Security