roblox hack installer.exe

Wecan Software

This is the Verti bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application roblox hack installer.exe by Wecan Software has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Verti Setup installer. The file has been seen being downloaded from s.allfreesoft.net.
Publisher:
Wecan Software  (signed and verified)

Version:
1.0.1.0

MD5:
977ac3fc4a0a1fefadf4ca27773e333c

SHA-1:
a8eeb54b3443cac2b3b5c730a9d9d070954b1f68

SHA-256:
e661667df3cf54f696cee8ade60b0746a03bf3fa3aba59e139d4feb2f406e91d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/28/2024 2:50:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Verti.WecanSoftware.Bundler (M)
15.12.25.0

File size:
245.8 KB (251,720 bytes)

Product version:
1.0.1.0

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Verti Setup

Language:
English (United States)

Common path:
C:\users\{user}\downloads\roblox hack installer.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/22/2014 9:00:00 PM

Valid to:
7/23/2015 8:59:59 PM

Subject:
CN=Wecan Software, O=Wecan Software, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1FD8A9E8CBFDDB2724A69194C505EF77

File PE Metadata
Compilation timestamp:
1/29/2015 1:08:12 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:zAFq2zBzxeO1bKPRx6vmSd/wu8JpLcXcy/2xRoS0L:zALeEKJgvgRcMy/IRoS0L

Entry address:
0x169280

Entry point:
60, BE, 00, 00, 53, 00, 8D, BE, 00, 10, ED, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 55, 79, 16, 00, 57, 83, C3, 04, 53, 68, 76, 92, 03, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
232 KB (237,568 bytes)

The file roblox hack installer.exe has been seen being distributed by the following URL.

Remove roblox hack installer.exe - Powered by Reason Core Security