minecraft-setup.exe

Power Play Media

The application minecraft-setup.exe by Power Play Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Tomorrow Software Installer installer. The installer is marketed through download protals and search ads as Minecraft but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
FYI Fun Installer Setup  (signed by Power Play Media)

Product:
FYI Fun Installer Setup

Version:
3.9.3.6729

MD5:
345b9e9313a9eef5a69259fde0553579

SHA-1:
fde237da895b41dcb73483c9290a06abd4f8fa43

SHA-256:
086f09f539d5681c1910f5e82fb7d1b531618ae9c163fa28c88893ab85b07650

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/26/2024 6:42:43 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.TomorrowSoftware (M)
16.11.27.19

File size:
868.9 KB (889,784 bytes)

Product version:
3.9.3.6729

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tomorrow Software Installer

Language:
English (United States)

Common path:
C:\users\{user}\downloads\minecraft-setup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
10/13/2015 6:17:38 PM

Valid to:
10/13/2016 6:17:38 PM

Subject:
CN=Power Play Media, O=Power Play Media, L=San Francisco, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
42E6D7782DB3A869

File PE Metadata
Compilation timestamp:
10/3/2014 10:37:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:AyTohPU5CUVwmajfvK9ETAbkOjUqB/a2faeXv3Zm5299Dk1jrJeqj2pID8j7IPIY:A0qigmawbrJB/7RPZKm0m0PTEn3P6n

Entry address:
0x262B

Entry point:
E8, E0, B2, 00, 00, E9, E2, AB, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 81, EC, 1C, 02, 00, 00, 53, 55, 8B, AC, 24, 28, 02, 00, 00, 56, 57, 6A, 01, 55, C7, 44, 24, 24, 00, 00, 00, 00, E8, 3F, 3C, 00, 00, D9, 7C, 24, 1A, 0F, B7, 44, 24, 1A, 0D, 00, 0C, 00, 00, 89, 44, 24, 1C, 8D, 44, 24, 24, 50, D9, 6C, 24, 20, 6A, 00, 6A, 02, 55, DF, 7C, 24, 2C, 8B, 74, 24, 2C, D9, 6C, 24, 2A, E8, 1E, 3B, 00, 00, 8B, 4C, 24, 34, 8B, F8, 83, C4, 18, 8D, 1C, 0F, 89, 5C, 24, 14, 85, FF, 75, 11, 55, E8, 14, 3B, 00...
 
[+]

Entropy:
7.9690  (probably packed)

Code size:
52.5 KB (53,760 bytes)

Remove minecraft-setup.exe - Powered by Reason Core Security