lccar31e.exe

The application lccar31e.exe has been detected as a potentially unwanted program by 26 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from dm.portalprogramas.com.
MD5:
86f461aa5f8b6f075ed5741cf4ad27c2

SHA-1:
20edfe2096cfe586b311736302ea9dd0b60d7da2

SHA-256:
6863e361012b925851fbcc630aa05b6f609f17d8189f1777c97087995aa99341

Scanner detections:
26 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/27/2024 8:53:45 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Strictor.53582
355

Agnitum Outpost
Trojan.Agent
7.1.1

Avira AntiVirus
PUA/InstallCore.Gen
8.3.2.2

Arcabit
Trojan.Adware.Strictor.DD14E
1.0.0.425

avast!
Win32:PUP-gen [PUP]
2014.9-160215

Bitdefender
Gen:Variant.Adware.Strictor.53582
1.0.20.230

Clam AntiVirus
Adware.Installcore-134
0.98/21511

Dr.Web
Adware.InstallCore.128
9.0.1.046

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.53582
8.16.02.15.02

ESET NOD32
Win32/InstallCore.BH potentially unwanted (variant)
10.12208

F-Prot
W32/InstallCore.B2.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Strictor
11.2016-15-02_2

G Data
Gen:Variant.Adware.Strictor.53582
16.2.25

K7 AntiVirus
Unwanted-Program
13.2017125

Malwarebytes
Trojan.SMSHoax
v2016.02.15.02

McAfee
Artemis!86F461AA5F8B
5600.6489

MicroWorld eScan
Gen:Variant.Adware.Strictor.53582
17.0.0.138

NANO AntiVirus
Trojan.Win32.InstallCore.bdavxl
0.30.24.3283

nProtect
Trojan-Clicker/W32.InstallCore.613496
15.09.04.01

Panda Antivirus
PUP/Solimba
16.02.15.02

Sophos
Install Core Installer (PUA)
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-InstallCore
9323

Trend Micro
TROJ_GEN.R00XC0EI515
10.465.15

Vba32 AntiVirus
AdWare.InstallCore
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
43482

Zillya! Antivirus
Adware.InstallCore.Win32.799
2.0.0.2388

File size:
599.1 KB (613,496 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\lccar31e.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:qMmDKpySkj0iWOprm0eSc3IAOI//BUIDiYRDCuEXsvhWCQ7/ud5:qjuwSkwuXjqOIX2IGYtIgWCQs5

Entry address:
0x119490

Entry point:
60, BE, 00, F0, 48, 00, 8D, BE, 00, 20, F7, FF, C7, 87, 10, 77, 0C, 00, 2B, 40, 18, 00, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
556 KB (569,344 bytes)

The file lccar31e.exe has been seen being distributed by the following URL.

Remove lccar31e.exe - Powered by Reason Core Security