setup_489.exe

Jabuticaba Ltd

The application setup_489.exe by Jabuticaba has been detected as adware by 4 anti-malware scanners. This is a setup program which is used to install the application. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from downmyproduct.com and multiple other hosts.
Publisher:
shopperz   (signed by Jabuticaba Ltd)

MD5:
cc43b9558297af79908dfaed745f9f54

SHA-1:
b07b8a7c9f7db388ee9719c199a941e17b082d34

SHA-256:
045a7383c32cba3f8ebdd8367a36babbdb268b31a402eb06af2292614bd25257

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
12/26/2024 5:37:09 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Perion
7.1.1

Dr.Web
Adware.Shopper.816
9.0.1.027

ESET NOD32
Win32/Toolbar.Perion
9.11080

Reason Heuristics
PUP.Installer.Bitcocktail
15.1.27.22

File size:
3.8 MB (3,998,320 bytes)

Product version:
2.0.0.456

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\setup_489.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
12/2/2014 9:55:48 AM

Valid to:
12/3/2015 9:55:48 AM

Subject:
CN=Jabuticaba Ltd, O=Jabuticaba Ltd, L=Hod Hasharon, S=Israel, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121CEB9BA01C581709E445C7F51EA2C7992

File PE Metadata
Compilation timestamp:
1/30/2013 9:21:56 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:WBY9HnC5WQqqASzILxD3rpyfMz4POlUbx9nkAjxl+bi5p:W+ZnCXAYIlTrpqYUbxZkKP+bi7

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9895

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file setup_489.exe has been seen being distributed by the following 5 URLs.

https://downmyproduct.com/Installer/.../index.php?download=file&cp=sprz.exe&a_name=Shopperz

Remove setup_489.exe - Powered by Reason Core Security