openoffice - chip-installer.exe

CHIP Digital GmbH

The application openoffice - chip-installer.exe, “CHIP Secured Installer” by CHIP Digital GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Covus installer. The installer is marketed through download protals and search ads as the free Apache OpenOffice but will also install additional software offers which include adware, PUPs and browser toolbars. The file has been seen being downloaded from www.chip.de.
Publisher:
CHIP Digital GmbH  (signed and verified)

Description:
CHIP Secured Installer

Version:
1.1.6.0

MD5:
3f71d5745ccfc9a4fbe550f479ffb569

SHA-1:
96e6026e3cd9039287da664347783bb2f24bc236

SHA-256:
e86ca8eb4d977f2422512b8c9423a91df0d51a3ab817809c4af0bb457c15fe8a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/23/2024 2:30:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ChipDigital.Bundler (M)
16.8.10.15

File size:
1.4 MB (1,470,472 bytes)

Product version:
1.1.6.0

Copyright:
Copyright © 2016 Chip Digital GmbH

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Covus

Language:
German (Germany)

Common path:
C:\users\{user}\downloads\openoffice - chip-installer.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/27/2016 1:00:00 AM

Valid to:
1/27/2017 12:59:59 AM

Subject:
CN=CHIP Digital GmbH, OU=Download Development, O=CHIP Digital GmbH, STREET=St.-Martin-Strasse 66, L=Munich, S=Bavaria, PostalCode=81541, C=DE

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B0564F3FBF54F6269517864BB24329FC

File PE Metadata
Compilation timestamp:
2/10/2016 11:32:18 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:Sq5TfcdHj4fmbz2qh0smVkVMyTmXqvEzKJ9TtLb6OqX8N70zQJ9TtDCZf:SUTsamPxYXs5KX8B5+

Entry address:
0x1E7900

Entry point:
60, BE, 00, 40, 59, 00, 8D, BE, 00, D0, E6, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
336 KB (344,064 bytes)

The file openoffice - chip-installer.exe has been seen being distributed by the following URL.

Remove openoffice - chip-installer.exe - Powered by Reason Core Security