moneyrobotsetup.exe

Money Robot Submitter

softtech srl

The application moneyrobotsetup.exe, “Money Robot Submitter Setup ” by softtech srl has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.moneyrobot.com.
Publisher:
Money Robot srl LTD   (signed by softtech srl)

Product:
Money Robot Submitter

Description:
Money Robot Submitter Setup

MD5:
e78cb5d732fb9ae9cadd4e655c2937f0

SHA-1:
8f70bbcad21e25a92e2b41877a0aa4b2aa3d9279

SHA-256:
b8046d2470cea1e27c8219c12f6395cbfd2c6a6fddc9d65cce939f967c6e6ad6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/28/2024 3:20:37 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.21.2

File size:
5.1 MB (5,375,128 bytes)

Product version:
6.25.3

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\moneyrobotsetup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/6/2016 1:00:00 AM

Valid to:
12/7/2019 12:59:59 AM

Subject:
CN=softtech srl, OU=Software Developing, O=softtech srl, STREET=str. Patriotilor nr.18, L=Sibiu, S=Sibiu, PostalCode=550130, C=RO

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2A2CB80A1ED4A89D628518A2AD71738F

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xAA98

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 2E, 86, FF, FF, E8, 35, 98, FF, FF, E8, 9C, 9B, FF, FF, E8, B7, 9F, FF, FF, E8, 56, BF, FF, FF, E8, ED, E8, FF, FF, E8, 54, EA, FF, FF, 33, C0, 55, 68, 69, B1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 32, B1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, D0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, C2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, 24, 93, FF, FF, 8D, 55, F0, 33, C0, E8, 66, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
40.5 KB (41,472 bytes)

The file moneyrobotsetup.exe has been seen being distributed by the following URL.

http://www.moneyrobot.com/.../MoneyRobotSetup.exe

Remove moneyrobotsetup.exe - Powered by Reason Core Security