messenger.exe

The application messenger.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from messenger.logiciel-france.com.
MD5:
372fbf3dbdd6fab529c5dff7559655dd

SHA-1:
6e08888fe3cb686f9c347154fca38b1bd51a2437

SHA-256:
99f53bd9c3487b69579d47f593c485ec6b36e9f1efaf04428a87adfa56d9a6ca

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
1/13/2025 10:49:36 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.57.126

Dr.Web
Adware.InstallCore.55
9.0.1.041

ESET NOD32
Win32/InstallCore.AG (variant)
10.7900

F-Prot
W32/InstallCore.G.gen
v6.4.6.5.141

K7 AntiVirus
Unwanted-Program
13.158.8113

NANO AntiVirus
Trojan.Win32.InstallCore.bcjfdy
0.22.6.49175

Trend Micro House Call
TROJ_GEN.F47V0823
7.2.41

Vba32 AntiVirus
Malware-Cryptor.InstallCore.9
3.12.18.4

File size:
1016.9 KB (1,041,272 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\messenger.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:3i84nFRtjHlaa8RYPg69Nr8H/apQqtRy:3SnFRNFYaNr

Entry address:
0xC96E0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 94, 35, 41, 00, E8, 96, DE, FF, FF, 0C, 24, 8B, D7, 8B, C5, E8, 71, FD, FF, FF, 8B, 04, 24, 83, 38, 00, 74, 28, 8B, 04, 24, 8B, 40, 04, 01, 43, 08, 8B, 04, 24, 8B, 40, 04, 29, 43, 0C, 83, 7B, 0C, 00, 75, 10, 8B, C3, E8, 9A, FA, FF, FF, EB, 07, 8B, 04, 24, 33, D2, 89, 10, 83, C4, 14, 5D, 5F, 5E, 5B, C3, 90, 53, 56, 57, 83, C4, EC, 8B, F9, 89, 14, 24, 8D, 98, FF, 3F, 00, 00, 81, E3, 00, C0, FF, FF, 8B, 34, 24, 03, F0, 81, E6, 00, C0, FF, FF, 3B, DE, 73, 5B, 8B, CF, 8B, D6, 2B, D3...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
817.5 KB (837,120 bytes)

The file messenger.exe has been seen being distributed by the following URL.

Remove messenger.exe - Powered by Reason Core Security