little_big_planet_3.exe

Internet Explorer

Consortium Group ltd

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application little_big_planet_3.exe, “Internet Explorer Add-on Installer” by Consortium Group ltd has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
Microsoft Corporation  (signed by Consortium Group ltd)

Product:
Internet Explorer

Description:
Internet Explorer Add-on Installer

Version:
11.00.9600.16428 (winblue_gdr.131013-1700)

MD5:
6ef22fd9c04250397f7b9b7bd1cba0a3

SHA-1:
cf65ef178949c56b00fd944d790b5b8cf95c38aa

SHA-256:
cb98fb5b929663c47ec93cd5fcb5b93f51f00cb2a0c2be2ef44e3c5a890ecc99

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 8:31:58 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCube (M)
17.1.31.16

File size:
3.5 MB (3,623,016 bytes)

Product version:
11.00.9600.16428

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
ieinstal.exe.mui

File type:
Executable application (Win32 EXE)

Language:
Vietnamese (Vietnam)

Common path:
C:\users\{user}\downloads\little_big_planet_3.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/16/2015 3:00:00 AM

Valid to:
2/25/2016 2:59:59 AM

Subject:
CN=Consortium Group ltd, O=Consortium Group ltd, STREET="3RD FLOOR, C&h TOWERS,", STREET=CORNER OF GR.MARLBOROUGH UN GR.GEORGE STR., L=ROSEAU, S=ROSEAU, PostalCode=00152, C=DM

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D6D9F6CD54311DD57B715B621215CF32

File PE Metadata
Compilation timestamp:
1/9/2016 8:57:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x2E7230

Entry point:
55, 8B, EC, 6A, FF, 68, 58, 61, 75, 00, 68, B0, 83, 6E, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, CC, 60, 75, 00, 33, D2, 8A, D4, 89, 15, 00, A2, 75, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, FC, A1, 75, 00, C1, E1, 08, 03, CA, 89, 0D, F8, A1, 75, 00, C1, E8, 10, A3, F4, A1, 75, 00, 33, F6, 56, E8, CA, 0F, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, 95, 0C, 00, 00, FF, 15, B4, 60, 75, 00, A3, 34, A7, 75, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
3.3 MB (3,493,888 bytes)

The file little_big_planet_3.exe has been seen being distributed by the following URL.

http://5529e58c1b967b9b4861b2e8.downfastoloaders.net/.../?f=18be695e73899f30d9dbcc5d8d40d9c6ad7e4c12ac67cf662791facb91fdb40cb688420ab0c82e9ebc119e9af8f22c11a823daa758f0394399d3ebdc203be8ffc3327505e19700df988841ee1d31c071bbec83b6858c872e9c9cae6b964eaed6f08a7bdab3f4d7caf596494a13352fe1f91b3e1e4f0d4e53dcf66920a00fcb413fc36244783cf47b62650033c4e4acca6a020a2491eb6ef998a3cf2ba287e50190dc61c461a747d3e1fd2f9e743031e1651af606c4ffea468775858a3539fb694fe821018766dd49944f3753c8ea3e2751f91a97b6ab86ebc322b4f7e5f4fa45bfb7ca3d9b81866d06f934aeec556c58ee043dce0171b9bc1d7e1ba5ed04635f42a4be

Remove little_big_planet_3.exe - Powered by Reason Core Security