mp3rocket.exe

MP3 Rocket

SCCE Development Inc

The application mp3rocket.exe, “MP3 Rocket Setup Program” by SCCE Development Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
MP3 Rocket Inc.  (signed by SCCE Development Inc)

Product:
MP3 Rocket

Description:
MP3 Rocket Setup Program

Version:
7.3.2

MD5:
b5342f5c74b9ccbc2d69e3bebc940f59

SHA-1:
cabe4741366fe8817da732ae1cbf89bd20405a7d

SHA-256:
9a74c7bd38c50130132bd7ebb0c2a71164ea979bb8eafb542a1fe9dd4ccf9e30

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
11/4/2024 5:12:01 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OpenCandy.SCCE.Installer.Meta (M)
16.4.12.1

File size:
1.1 MB (1,193,592 bytes)

Product version:
7.3.2

Copyright:
Copyright © MP3 Rocket Inc.

Original file name:
MP3 RocketSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\mp3rocket.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/1/2015 7:00:00 PM

Valid to:
11/1/2016 7:59:59 PM

Subject:
CN=SCCE Development Inc, O=SCCE Development Inc, STREET=3051 W Maple Loop Ste 201, L=Lehi, S=Utah, PostalCode=84043, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EE6BCFEEB3DE758C0292441353CB7413

File PE Metadata
Compilation timestamp:
1/29/2016 12:27:53 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
24576:YeMTCNix5ykhnKfca+OT0vZC0l77oGm8OQhcB3uSZ:Y1FxQkh/a+OT0vke4GQwK+SZ

Entry address:
0x4F6F2

Entry point:
E8, DD, 04, 00, 00, E9, 80, FE, FF, FF, 55, 8B, EC, 83, 25, 2C, AE, 4A, 00, 00, 83, EC, 2C, 53, 33, DB, 43, 09, 1D, D0, 82, 4A, 00, 6A, 0A, E8, D2, 84, 02, 00, 85, C0, 0F, 84, 74, 01, 00, 00, 83, 65, EC, 00, 33, C0, 83, 0D, D0, 82, 4A, 00, 02, 33, C9, 56, 57, 89, 1D, 2C, AE, 4A, 00, 8D, 7D, D4, 53, 0F, A2, 8B, F3, 5B, 89, 07, 89, 77, 04, 89, 4F, 08, 89, 57, 0C, 8B, 45, D4, 8B, 4D, E0, 89, 45, F4, 81, F1, 69, 6E, 65, 49, 8B, 45, DC, 35, 6E, 74, 65, 6C, 0B, C8, 8B, 45, D8, 35, 47, 65, 6E, 75, 0B, C8, F7, D9...
 
[+]

Entropy:
7.2521

Code size:
527 KB (539,648 bytes)

The file mp3rocket.exe has been seen being distributed by the following 31 URLs.

http://www.mp3rocket.me/.../MP3Rocket_Setup.exe

http://www.mp3rocketnowbest.com/c?x=f2m2OsqMhw/3zKTVGtlBkVrn85GLN263bO8ePh50V6A=&c=Xpk5Ugi7bS 3MPjhkXHPXS V9jW1COdN4V qDMdUMzeons6rEGz/oBvzQ1STIa Mukb6JSh430S2oz3uFxrMaNjy8105TUwenEFotBRGPRvgXi0Em9IQlzzJb0eXdyaA8bMLubaFULE M3CoNrlbd0KXbxupn7Ir I9eFUcuojA=&downloadAs=MP3Rocket_Setup.exe&fallback_url=http://www.safefiles.net/.../mp3rocket.exe

http://www.mp3rocketnowbest.com/c?x=55byF acfegOLQUjv5twvnUXp/hHDK91qpxsDDrkuz8=&c=0OhlocgaS1zcaqfgLUF3ymv3LEr 8Xs6L 93AN2aCpWF8DNVxJaGeEZ09JtLYEmLYPgIFDNNOBj USYUPKMgQkedTR 2eT4Gl Zgu80jfIsIF3yNKhnzG/VwRYrK10BqNBAU3XhZoDLFtQMdvUrvpw==&downloadAs=MP3Rocket_Setup.exe&fallback_url=http://www.imusicsearch.com/.../mp3rocket.exe

http://www.my-free-kazaa.com/.../mp3rocket.exe

http://gsf-cf.softonic.com//9d0/5ab/.../file?id_file=54821&channel=WEB&instance=softonic_es&type=PROGRAM&fdh=no&SD_used=0&Expires=1375265678&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=fUiExIdwB44feB4NNgKJIYVKvBPEy8lOyLho8uCyuQVdnuhQbi72IIaSt8SILUYjTLLPcEAh4q4mQQrMjfDT5VSZRB~emWvwYZN2WJMwrn-dL33b3h~lVS8uR2FSOZitTbLGAsJ9f~Z4R3bBR3nJh9-FgqiZfzPBKtKbxx3A-dc_&filename=mp3rocket.exe

http://software-files-a.cnet.com/s/software/.../88/29/.../mp3rocket.exe

http://www.safefiles.net/.../mp3rocket.exe

http://www.free-music-downloads.cc/.../MP3Rocket-Win.exe

http://gsf-cf.softonic.com/5ad/03a/.../mp3rocket.exe

http://www.mp3rocket.com/.../mp3rocket.exe

http://software-files-a.cnet.com/s/software/12/65/34/.../mp3rocket.exe

Latest 30 of 31 download URLs

Remove mp3rocket.exe - Powered by Reason Core Security