minecraft.exe

Zoobam

This is the Tightrope WebInstall which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application minecraft.exe by Zoobam has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the Tightrope WebInstall installer. With this installer, users are expecting to download Minecraft but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Zoobam  (signed and verified)

MD5:
b50030d4dee60f70ea5cefcf3fe3b0e6

SHA-1:
56ce47217aa5af50521306f690adbac9cedd928e

SHA-256:
a1e349d0e0ed345ff2e208a542ead5442ea8639dd968cdabe6b5186dcb990dea

Scanner detections:
8 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/16/2024 5:48:30 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/DownAdmin.prfb
7.11.209.38

AVG
Generic
2016.0.3203

ESET NOD32
Win32/DownloadAdmin.I potentially unwanted application
9.7.0.302.0

F-Secure
Adware:W32/WebInstallBundle
11.2015-10-02_3

G Data
Win32.Application.DownloadAdmin
15.2.25

Reason Heuristics
PUP.Tightrope
15.2.9.12

VIPRE Antivirus
Threat.4783369
36694

File size:
75.6 MB (79,312,264 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tightrope WebInstall (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\minecraft.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
10/15/2014 9:27:59 PM

Valid to:
10/15/2017 9:27:59 PM

Subject:
CN=Zoobam, O=Zoobam, L=Kirkland, S=Washington, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4EA9D31E75E043

File PE Metadata
Compilation timestamp:
1/29/2015 12:35:11 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:uKCFG+pl1Hp7p4ZkuRt4Zh3UdOxouSdWE7uglrB/jmN7Trkfcn+z6:u3Xxp4Zkuf47kdtdZ7uC/jmlrDn+z6

Entry address:
0x234A

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 78, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, E8, F8, FD, FF, FF, FF, 15, 30, 77, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 2C, 77, 40, 00, 6A, 08, A3, 98, 3D, 42, 00, E8, DD, F9, FF, FF, 53, 68, 60, 01, 00, 00, A3, A0, 3C, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 0B, 74, 40, 00, FF, 15, 50, 71, 40, 00, 68, 00, 74, 40, 00, 68, A0, 34, 42, 00, E8, 5A, F3, FF, FF, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57...
 
[+]

Entropy:
0.1352

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove minecraft.exe - Powered by Reason Core Security