minecraftfreedownloadsuscom-setup.exe

Fast Downloader Media

The application minecraftfreedownloadsuscom-setup.exe by Fast Downloader Media has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from files4.downloadnet276.com and multiple other hosts.
Publisher:
Clever Small Installer  (signed by Fast Downloader Media)

Product:
Clever Small Installer

Version:
93.5.1.606

MD5:
3e9940f98eb13f69328b3c9dbb0cb861

SHA-1:
d99ad3a21669cdb9341d1a283ed764751db63195

SHA-256:
ea6d96fd18aa7fbc29f20b07d791affa5ab6faaef115b7b4ce508174509bdb39

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 12:09:58 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.DownloadAdmin.4
5813571

avast!
Win32:Malware-gen
151217-3

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.DownloadAdmin
10.0.0.5366

ESET NOD32
Win32/DownloadAdmin.P potentially unwanted application
7.0.302.0

F-Secure
Riskware.Gen:Variant.Application.Bundler
5.15.21

Norman
Gen:Variant.Application.Bundler.DownloadAdmin.4
17.12.2015 06:34:11

Reason Heuristics
PUP.DownloadAdmin.FastDownloaderMedia.Installer (M)
15.12.5.20

VIPRE Antivirus
Threat.4150696
46020

File size:
883.9 KB (905,104 bytes)

Product version:
93.5.1.606

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\minecraftfreedownloadsuscom-setup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
11/6/2015 5:05:38 PM

Valid to:
11/6/2016 5:05:38 PM

Subject:
CN=Fast Downloader Media, O=Fast Downloader Media, L=Oakland, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B4708E52D08AC36

File PE Metadata
Compilation timestamp:
11/7/2014 3:01:11 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:o3httXZLnq24LwexEAz+wpWEta3k4f6CL8:MRX9nqNLweYwja3k4SC

Entry address:
0x40B2

Entry point:
E8, 69, 94, 00, 00, E9, 6B, 8D, 00, 00, CC, CC, CC, CC, 55, 8B, EC, 83, E4, C0, 83, EC, 34, 53, 56, 57, E8, 2F, 23, 00, 00, 8B, F0, A3, 30, C1, 44, 00, 85, F6, 75, 15, 68, 10, BF, 44, 00, E8, 5A, 08, 00, 00, 83, C4, 04, 6A, 37, FF, 15, 70, F0, 40, 00, 68, 00, 01, 00, 00, 6A, 00, 56, E8, 62, 24, 00, 00, 56, E8, 7C, 22, 00, 00, 8B, 5D, 08, 6A, 00, 53, 56, E8, 60, 24, 00, 00, 33, FF, 83, C4, 1C, 89, 7C, 24, 3C, 85, DB, 7E, 34, 8D, 49, 00, DB, 44, 24, 3C, 83, EC, 08, DD, 1C, 24, 56, E8, B0, 21, 00, 00, 8B, 45...
 
[+]

Entropy:
7.9646  (probably packed)

Code size:
53.5 KB (54,784 bytes)

The file minecraftfreedownloadsuscom-setup.exe has been seen being distributed by the following 50 URLs.

http://files4.downloadnet276.com/dl-pure/.../?bc=1195659&checksum=696645&cb=918156750&executable=1197345

http://files4.downloadnet276.com/dl-pure/.../?bc=1195659&checksum=696645&cb=1973984464&executable=1197345

http://files4.downloadnet276.com/dl-pure/.../?bc=1195659&checksum=696645&cb=769743581&executable=1197345

http://files4.downloadnet276.com/dl-pure/.../?bc=1195659&checksum=696645&cb=-453479577&executable=1197345

http://files4.downloadnet276.com/dl-pure/.../?bc=1195659&checksum=696645&cb=412335568&executable=1197345

Latest 30 of 116 download URLs

Remove minecraftfreedownloadsuscom-setup.exe - Powered by Reason Core Security