mp3rocket_setup.exe

Sal

MP3 TechSupport LLC

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application mp3rocket_setup.exe, “Sal Setup ” by MP3 TechSupport has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.hostflashconcepts.com and multiple other hosts.
Publisher:
Duto   (signed by MP3 TechSupport LLC)

Product:
Sal

Description:
Sal Setup

Version:
4.8.4.5

MD5:
814066562ad01352b1bf2f60d890cbb5

SHA-1:
a1bc9055861f69178dbecd8f6cf9e70c7792235f

SHA-256:
d5ed94c87fdb29ad55453494c18232d930d39768297c9fbfc74d00d914777545

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/5/2024 9:53:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.MP3TechS.Installer (M)
16.6.29.12

File size:
1.1 MB (1,133,968 bytes)

Product version:
3.8

Copyright:
Wizard

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\mp3rocket_setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/21/2016 2:00:00 AM

Valid to:
4/22/2017 1:59:59 AM

Subject:
CN=MP3 TechSupport LLC, O=MP3 TechSupport LLC, STREET=3051 W Maple Loop Dr Ste 201, L=Lehi, S=Utah, PostalCode=84043, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0081ECF0B90414131BF9016277516512CB

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:2JiVXe03sqdBs0XCTpb9YS74oZJ8eQmZwnJIuDUfTJlJM:2oVOld0STFn408eXGJIuQf1Y

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9038

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file mp3rocket_setup.exe has been seen being distributed by the following 39 URLs.

http://www.hostflashconcepts.com/c?x=O6d4KlAneWTJ3v8pgsFh2vh4BgjfPTZBiqD4CE5m6ZU=&c=7y1Zn M7BmaZVFc2XU2kRTM7ORi2k7i6v4ymZOfOnf52OBQyGk5IDi98ENdB7Z0/ok1A6yyTP kPk PfTzwAcMCNffAEMjz6nqodFgNBnhLcj9/NROHADDC0v52LGMdO&downloadAs=MP3Rocket_Setup.exe&fallback_url=http://www.imusicsearch.com/.../mp3rocket.exe

http://www.hostflashconcepts.com/c?x=Pv VuFF9gadhhaI a58RFedioHSnx bpPTjPBDgEDlA=&c=fj7PLoLtrLaKr0CT5RZd/xpMNf7mLD 19 d14IbFo6pWO3pZvsT7 zkPiVhrfT/0rGl22aqlPM/4H/azx/VCR6DGGnaLDX69J3WdKmiWdFY09C58AhsIuCSf9a8SdPE/&downloadAs=MP3Rocket_Setup.exe&fallback_url=http://www.imusicsearch.com/.../mp3rocket.exe

http://www.hostflashconcepts.com/c?x=8C75G8YV7hrr3xWzKmZw3Ekb8MgwEXhONNXMMq5S0lw=&c=Xj i7VfriLOtJMUZ4X7ZorTVbj3vyz1yg8HIYJngZLFu183N81IZobC40ThBB6Z53VauREwmd81FTZOYGGfgjSGC94yq71LMbzCFXvhFKyIAIT hBvoykDvupmo tym/&downloadAs=MP3Rocket_Setup.exe&fallback_url=http://www.imusicsearch.com/.../mp3rocket.exe

http://www.hostflashconcepts.com/bNEWofCEUiUMVIlqkzEB8HRppTi1zaL313knS IQhf43mqeyGABpwkRqMAz0Ji5m2OInQhYMBiE5dbu97JWjtf5GdsZSKNVm7WXPkcjmCo1l4RtX53f_so aejpPLoJDh0p01cTy58GcXWwCLciMJqQcbTE1ol3FPPTPaiSg_0ByYCqmGIE=-GzIAAAR0Y7H94TEvGARBgw44BuydRBYGG2NnCVKN_MYYvwVlZqfYt 5J1OPEAw==

http://www.hostflashconcepts.com/TFFUr9LgnUWbpR1AfIvx0fRr6ghYL1cymRskjvNhDEn8lx6LpL0ASn_NVhY3vT3uPcds26Fgt oNpE9Wx5KI Kp BB4gE6pcvOy4Hl4sEutejonjaDxcYMZrnwHNfi95HGOHOe 8MJdZnpSLI_NzQTVM6vHmxAuildiCmAIEcn8eRS0hpOQ=-GzIAAAR0Y7H94TEvGARBgw44BuydRBYGG2NnCVKN_MYYvwVlZqfYt 5J1OPEAw==

http://www.hostflashconcepts.com/c?x=nbGINNTO9lHr0FQB6cf/QQXqmoiUtMJ8dF6n7FvF7k8=&c=jTmcdnNYAjaqqNPAKP3xEhEVO9NvCkXh215cnmsr8Kxu1oQODbLWGM1HCVbkq GhJqS7vSwhp/AzKPnOr jq5V Zy4v7GAxAq p7X/pKuJ4sEximJXP8wbmxgKqLAmG&downloadAs=MP3Rocket_Setup.exe&fallback_url=http://www.imusicsearch.com/.../mp3rocket.exe

http://www.hostflashconcepts.com/ sJRdwooiUXf9KzHM8e7iU AiYx95xPMul5sQBOufqxJrVjEt4aoPE2NFqyIL58bYl1B E6aXJ2MUYEp7qOtt NaxXOxyTqEISK1coDf4nWcX9raH82lQHX1Z9rYSQM8B7y24J0FAd2iCDifhrr7KtCIqIdQmmtTBCL4mQ9AXCiO4bn8 CQ=-GzIAAAR0Y7H94TEvGARBgw44BuydRBYGG2NnCVKN_MYYvwVlZqfYt 5J1OPEAw==

http://www.hostflashconcepts.com/c?x=DYwNp4DZoHq8HWvvmQ7ush2mHS3bn/1U5pbwWFETqts=&c=zriRx/uLdEnt4UiAr5V9sLZ2sP5ATulalOAi3WDxXWfJJ0sMN/I9vfq/VBIskCk lHemzaxu4f1sC3qV3xkNaod INOab0/zKFd3CFP/LX5Yxwxx5W5GkpxaRpzixdQq&downloadAs=MP3Rocket_Setup.exe&fallback_url=http://www.imusicsearch.com/.../mp3rocket.exe

http://www.hostflashconcepts.com/c?x=5QaUn9xjDhxz7llnnljyYe3u8rGVlbMNsLFNxz1MOEA=&c=x8Wcw6FjnyRy9k4OSNBrfXzHUBre45SFOYMgGka2FhpELTNJrwkFYGs9PD2sXl75oHkE/FuXO9AEcXiCJv56FZCgB0vz95jFf7LlB/CAT 0VUzFEVqyBiTHCjVXdMUC2&downloadAs=MP3Rocket_Setup.exe&fallback_url=http://www.imusicsearch.com/.../mp3rocket.exe

http://www.hostflashconcepts.com/c?x=d3 VGi6VUosSA5nKBPScNCzLHNHvjfm6o7P7n26Zs8M=&c=c9O2btaHO/J1kmh0Naqp06o256OSwvETJiMyb6c4ZPRRBgyKiOc96N6s6z3S9T7yt r/tusFfo9AAwdX07E2ZYkudBUu76bhNk4lQDAA1YhcyhfwJZ2Fg5f5WkCT O1N&downloadAs=MP3Rocket_Setup.exe&fallback_url=http://www.imusicsearch.com/.../mp3rocket.exe

http://www.hostflashconcepts.com/c?x=4r97UBRzqcbZFsz37Src7AUd9oY8EJIQg4kzPAjGPKY=&c=b6T1s7D2QCoMJXm/rCC1tvA2jaCZ097m7tXt1HzO5zbr/RZT32ZpX4iEn9nAP4FNfY38tLzeKCiqR72z5w0XBu/LV a7HDaU6K2jq8ZLnubQsJlHkLdw3ZQMRjfMlb9z&downloadAs=MP3Rocket_Setup.exe&fallback_url=http://www.imusicsearch.com/.../mp3rocket.exe

Latest 30 of 39 download URLs

Remove mp3rocket_setup.exe - Powered by Reason Core Security