minecraft-setup.exe

Spiral Media

The file minecraft-setup.exe by Spiral Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Tomorrow Software Installer installer. With this installer, users are expecting to download Minecraft but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
FYI Fun Installer Setup  (signed by Spiral Media)

Product:
FYI Fun Installer Setup

Version:
3.9.3.6729

MD5:
2ee04f6838abba13ea97644f606ad1dd

SHA-1:
e9e8469849d8781e3e8ee5c14a79cd6139155859

SHA-256:
b7eaea3cf8b9a77d81c6eb0537c6c4fd71932c918b741ee175b72bbb6d4410f9

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 6:37:46 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.TomorrowSoftware.SpiralMe.Bundler (M)
16.7.14.8

File size:
868.9 KB (889,768 bytes)

Product version:
3.9.3.6729

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

Bundler/Installer:
Tomorrow Software Installer

Language:
English (United States)

Common path:
C:\users\{user}\downloads\minecraft-setup.exe.305wvd8.partial

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
10/13/2015 7:17:39 PM

Valid to:
10/13/2016 7:17:39 PM

Subject:
CN=Spiral Media, O=Spiral Media, L=San Francisco, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
6FFD2B025FCB30E8

File PE Metadata
Compilation timestamp:
10/3/2014 11:37:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:QyTohPU5CUVwmajfvK9ETAbkOjUqB/a2faeXv3Zm5299Dk1jrJeqj2pID8j7IPIi:Q0qigmawbrJB/7RPZKm0m0PTEn3P6F

Entry address:
0x262B

Entry point:
E8, E0, B2, 00, 00, E9, E2, AB, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 81, EC, 1C, 02, 00, 00, 53, 55, 8B, AC, 24, 28, 02, 00, 00, 56, 57, 6A, 01, 55, C7, 44, 24, 24, 00, 00, 00, 00, E8, 3F, 3C, 00, 00, D9, 7C, 24, 1A, 0F, B7, 44, 24, 1A, 0D, 00, 0C, 00, 00, 89, 44, 24, 1C, 8D, 44, 24, 24, 50, D9, 6C, 24, 20, 6A, 00, 6A, 02, 55, DF, 7C, 24, 2C, 8B, 74, 24, 2C, D9, 6C, 24, 2A, E8, 1E, 3B, 00, 00, 8B, 4C, 24, 34, 8B, F8, 83, C4, 18, 8D, 1C, 0F, 89, 5C, 24, 14, 85, FF, 75, 11, 55, E8, 14, 3B, 00...
 
[+]

Entropy:
7.9690  (probably packed)

Code size:
52.5 KB (53,760 bytes)

Remove minecraft-setup.exe - Powered by Reason Core Security