setup_imgburn_2.5.8.0_dlm.exe

Cobehi

Digital Digest Pty Ltd

The application setup_imgburn_2.5.8.0_dlm.exe, “Cobehi Setup ” by Digital Digest Pty has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.sharemegatowers.com.
Publisher:
Digital Digest Pty Ltd  (signed and verified)

Product:
Cobehi

Description:
Cobehi Setup

MD5:
a70bf19708048373d944c776d7edcad8

SHA-1:
3018fd8952324e8ee877c8083f77dd80188cb864

SHA-256:
e513a05a555bf77c264220e3085fc4ca77b574025dbea12ab8811ebb72e55dfe

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/27/2024 6:55:35 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.IM (L)
17.2.28.2

File size:
1.2 MB (1,273,016 bytes)

Product version:
5.1

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\setup_imgburn_2.5.8.0_dlm.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/1/2016 4:29:52 PM

Valid to:
2/11/2018 5:08:02 PM

Subject:
CN=Digital Digest Pty Ltd, O=Digital Digest Pty Ltd, L=Templestowe, C=AU

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G3, O=GlobalSign nv-sa, C=BE

Serial number:
28FDEF667CD17A44281EC77D

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file setup_imgburn_2.5.8.0_dlm.exe has been seen being distributed by the following URL.

http://www.sharemegatowers.com/kYJuRGoeYCjsCHiNHYNyw8 aLnuR04CqvQW2qEfxfVGxKxBgkT0rU1a6ddSh74L5i0AnhTGZuDDYUR4SIT f8iTQ hFtCD7wd2uqp_UldxawWRixZ_x0laJCx1 dDTCmDy KZtnRc63ZqNuvsBYlQMSK8wiiatr4lfY0_fqCHNzaz5ppexBoRzFhTeW2aS4k1xbvMz7XHEN u2bS2MDV6nLW89y1xvL05vE_1xT9XisMoosARKJe t sMSqJ20QkECPGiW_QE9FmRPVY1GrVqmdnUAU2Ng6TKeUkeXTRekbqWXdb1h7ZzLmeHdwzsZRfehDkZX4e9D4ZqaT4iYMh hMGVKa33YVSJpajRgNwM1R2eAcktBUVEPi7DkSxu_eRhNHdDoU3LBNKUQNHmvXRGUc3vQc6utZfMKDkur09Fv82 AixLCmRBWZtOf9idYhxveynDy2C9Zpfmd3rsJ2TfwDnuUtmA==-G3gAAOTwmtnhMnAis_oMpxw4tIISbzvwHS9256GOPxWJfeM1VtB8qPeO9FIyFk_Dr8KU 1t6FJpAf24xpJ3xuOYh5WagD9xbazloxisjxnIl2UCUaWqUnBdix8EC

Remove setup_imgburn_2.5.8.0_dlm.exe - Powered by Reason Core Security