setup__2834_i45994058.exe

Installer

WhiteSmoke Inc

The application setup__2834_i45994058.exe by WhiteSmoke Inc has been detected as adware by 8 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from i1.stylezip.info and multiple other hosts. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
Amonetìze  (signed by WhiteSmoke Inc)

Product:
Installer

Version:
1.1.3.71

MD5:
285b19e95172ba29936c3f2a0addf113

SHA-1:
6b5e70b3c2adcf4f70ed8e1f6c5357c0a55492dc

SHA-256:
e593cd4779aa7461bff1406765f72abcc70a3b70663e28133960cb5da0acb8e2

Scanner detections:
8 / 68

Status:
Adware

Analysis date:
11/23/2024 8:14:09 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen2
7.11.122.154

avast!
Win32:WhiteSmoke-A [PUP]
2014.9-131125

Boost by Reason
Adware.Installer.WhiteSmoke.V
2013.8.4.12

Dr.Web
Adware.Downware.1400
9.0.1.0329

ESET NOD32
Win32/Amonetize (variant)
7.9190

K7 AntiVirus
Unwanted-Program
13.174.10656

Reason Heuristics
PUP.Installer.WhiteSmoke.V
14.8.7.22

Sophos
Amonetize
4.96

File size:
150.8 KB (154,448 bytes)

Product version:
2.1.12

Copyright:
(c) Amonetìze , 2012,2013. All rights reserved.

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup__2834_i45994058.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/6/2013 5:00:00 PM

Valid to:
8/5/2015 4:59:59 PM

Subject:
CN=WhiteSmoke Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WhiteSmoke Inc, L=Wilmington, S=Delaware, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
55439B87CB55E81147C072F06F4F77EF

File PE Metadata
Compilation timestamp:
7/28/2013 1:00:16 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:uW1T7SxS/tBcvQxzR899HKhHIt64rIIr4FwRIDIPYNt9Bp26:usTL/ncvQs9got64sIMFwi0YjzI6

Entry address:
0x5CFC0

Entry point:
60, BE, 00, D0, 43, 00, 8D, BE, 00, 40, FC, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8003  (probably packed)

Code size:
132 KB (135,168 bytes)

The file setup__2834_i45994058.exe has been seen being distributed by the following 2 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove setup__2834_i45994058.exe - Powered by Reason Core Security