setupimgburn_2_5_8_0.exe

Manikoguc

InstallSpeedy (New Media Holdings Ltd.)

The application setupimgburn_2_5_8_0.exe, “Manikoguc Setup ” by InstallSpeedy (New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.capitalcenterdl.com and multiple other hosts.
Publisher:

Product:
Manikoguc

Description:
Manikoguc Setup

Version:
2.5.1.4

MD5:
c62c1642a6123f20f38d18b728987bc1

SHA-1:
a8a4d37a1fc4c630e7031f959db99c416aa785e4

SHA-256:
5c36f19cd1aef877410a211d63cfbc53030b6988fb62b68a9f9cc58a19c035c0

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/27/2024 4:12:11 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.NMH.Bundler (M)
16.7.2.23

File size:
949.5 KB (972,296 bytes)

Product version:
1.5.4

Copyright:
Lite

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\setupimgburn_2_5_8_0.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/15/2016 7:40:35 PM

Valid to:
7/11/2017 5:28:33 PM

Subject:
CN=InstallSpeedy (New Media Holdings Ltd.), O=InstallSpeedy (New Media Holdings Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F59EA8A6B04CAE5E738F6CB09D295BDB

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:NniB9o6RVP79S79fL7mrDFnlujcKecVJnfZI:AbpRpZS9L7oBQQqVJnxI

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file setupimgburn_2_5_8_0.exe has been seen being distributed by the following 19 URLs.

http://www.capitalcenterdl.com/cpS3VeTvTTrUVAAkGdzBTER0_m3Bi9hHmOFF1BCjWKLgM04QWht4HsS4WdYk8zc_i9Te22AYXNVuo_KqpBjw9zxsHA0TlBogpaEKJ2n6PPpUeDnmU5jyFOAkf2NzmHD1ch8A7cLt4 uaAa4l3k 3hT4a6wlJoTfoT3tEFcgq3l8cSAE23F8h0sEfKDobgAg990fVn_LkLOBYSrRn8v8k2yy9Il3c7tehIhhUHbS82zv4Lazm9UOQ4to0Fdb4 NFoLBZmcTnsqQIa4m43h1Hj9PIvmbwHiXXlIqVL2 Rf_KCWIzP5kfiURpLICDnDgpEaXoq3nuxjVFaq83XJm752OV5wAEmi8b51Tp32f9gQGYJkl26Ep3w92Tt0IYcPmxK1pY9eUHr_yuUNZW4ODxEyjOYavXyeTc0AJjUjOqkIEFXvsbTMcSWTRw8kPOktrKXIZwEJTd2PHFPUsFYWinpKNElKtVUI7nL_v1ckQFIQy3cliMMe6NWoTCOAB3bJwdk4o9cGJut-GzkAAEQ3F5Mh2oIiiKAb J DQw7Y_0VSYBh4DJ9j8Uj5ZI1Rvr9FIS_ZR4IfwYA1LSr0 FCtSTs=

http://www.capitalcenterdl.com/c?x=PrH9UG79 zZtGc3SQUaI3jPkH J6Iiwu3fp3vvbhJwE=&c=4lwEWu2fDTi198T5OxVCn6qI3Pa63a67Ec1LcDpY2Tvf9EMZPPegPd5MvMmfwlDMPw4olsXuXdVTz4Xu3B2vPut6wGvKfx21vbiA97owlHuAU11gI5GvgN3KsJLMY3wU&downloadAs=SetupImgBurn_2_5_8_0.exe&fallback_url=http://.../download.php?file=imgburn

http://www.capitalcenterdl.com/av60gNv7nwom93m pCetCoPbtS2 lUecJmDzzWfEOvRPQj6OkPk4mqqpuWg2Il2UYuieII0IrnnfX1xpq6cv7UypzAlmz0vQUVa8qHUcxJquFcCBNTlN5 xyqhx7vTIuqds3trhJCbDLiK1yoSuS0AYrYmW7nO aO41fy u8pNQYpwReteqSnTUbwqiAzS3OkswPp9Qsqwl6N51049JW1xXiAVqqJMq494a8ujzmVgJT9zqLsnVCk7wftCapvWmjMo 8ZEesrv6k3cNEij_L2B_V_61iCmEU9tDTMF49xgTkzkRJMWHO2tqwZjlfmaY0iKIU5DbxahzO8GZV74 YpYjIWH558DCzbdIpjOjg6N7SxXEddy9GvQcozL411SJeeOpnadvuukjoL276WVAgjQeZfxPmazkJgGfOsdJ_4iI1WYzjuDxEpF9s_cM_jFLO3OylAD9Oke2EzuiqEs5eYLiv75BwPvnSS_vqgpZvmoJmtlYX7mQjC1WxKUBfyiEE5X5A6orz-GzkAAEQ3F5Mh2oIiiKAb J DQw7Y_0VSYBh4DJ9j8Uj5ZI1Rvr9FIS_ZR4IfwYA1LSr0 FCtSTs=

http://www.capitalcenterdl.com/TtVG0fDZmt9VIWEEPCS3IyivxxLsSox13c_wSp5EHCv7BkC02qL60OZgdujbOpwWtHgujLL3aPhpI4vsb1Om9btd6aC8VlyyFqhsvaKKfi0t_oPmSEiX1CUo3ybnP5AvzoO5uuS6CG92NyOZaVCTsAioBxnz4GK6lnRGMY6167K7DkWRTq3h_3ruUUdqO33XwtyqDi4sLQhjTdjToFOVk7aeuwCVAi3XTjg337yWGfWzlOkH2F69fSygAxTa6DtVpVUBtH8HAFSMFGB1l1vHnzPIZhzpvXH72RPpVCy2L7HcbZdnvhGYaU19V0ajpMyyPxVziV1kuSwrrYiwAoe4p9t0CIjpNOYcyyWRepwhoSVDjb45ixRfqf b9Z5Aaawpd2VHwq hJLefLPzgjUwMwopHpCJ1gmMdayiMvR2duNfysPD0 J2YAPfEqjSje2ap7nPtqW yS4J14xoFMnx0FJh76Dc _p1 gzjGe8eK7nttfC4jRBkwUhAJ2wPUIt4itmN1hXhu-GzkAAEQ3F5Mh2oIiiKAb J DQw7Y_0VSYBh4DJ9j8Uj5ZI1Rvr9FIS_ZR4IfwYA1LSr0 FCtSTs=

http://www.capitalcenterdl.com/c?x=wVQdv9rk/ gtYeBn0q/xKDTTRAGRx8WN/uySmwZIFHE=&c=/HSPjdLqH/moANsUVwREyCZln95DVjWZg8 NNL9JcVayUm 8D WTsn5RlydyLtdbVAatGJKFmZwjhLhsHgI4DqGyX8KgHtBtaUHli5/ADXCRXfS2miQf/Dqi7FFpBAF6&downloadAs=SetupImgBurn_2_5_8_0.exe&fallback_url=http://.../download.php?file=imgburn

http://www.capitalcenterdl.com/3LyDnKFyFTjWfStYOYk0i 1tJ0WdopR2KqEZNM5KDwuAmKNQ9GtqvTAl9VdHoZpD029qwV0Etglla194IsYwC1PyUre_8Hgh2oEpxoHlWcpS_eJLFm8l6NoqKSBtqt6SeUYu 5dLpeQ3vkiLRSSw3MclEqZIuCoAPsEwx9J6tCSt0U2Cgt8eGBrFQuBRU7OyU3sUPOkbyjGoOWJrWGQsY5MrU9MjAD82NDdXK13Ct6QHVxObSz_H_9lmafxKrSEKfMZofEQxwJDARFwcbh3ocjs_LlueOcWzCQMduaOpFAxJP_6H3QrZ95 4H_UVmIOx6dEpUW9FbUmn_FB7J0TfRg5dpuDJGYXkNTi0xFHslFz6BXdXL8ZKHlqhdKIDpWQDkk1xjKLtw3RWVfavj7wrpnnC7pZX wSZL1 01FvK6g87G91dS42Zm38XBHQOjicD297ty2qp2tcRgPErGdm7iM6NS0Fs37PbTPHv3 kgppnf26h7Usbrx0VnkYDu77OxLzCLyn55-GzkAAEQ3F5Mh2oIiiKAb J DQw7Y_0VSYBh4DJ9j8Uj5ZI1Rvr9FIS_ZR4IfwYA1LSr0 FCtSTs=

http://www.capitalcenterdl.com/13_t7fMUOXNOm eoPGq8XOJhYLaAeFoiEkxZefP1uOVb1cx1Ku2PUABKgG tOttKCDF7YUQ20uF5KPFtVkP17jeEZdBdyhW_OoqWM0aa6MgeZ6R6XAN94cPEDT4fngJjJTNT7l7aczsecjOPl1XrvRBbHKOunutrQM6qZM6jIUcvbnV1xsRcxFGnM8eHpDPF29tfuqz742HcHPzvhPBN33y7tCKmBO9DGDGwL8CRgyDk_3Lgn04qQ7WmcNjaHMzqL2ZMPRGSfAo0rVVhc3Z41RolYEuKJFX4wAJ8zcTP0yznVR6TnJS_PWWmgSaHiszsl6DU7lZT82Zt1N1cwmDA7KDNL C7VmIResqvvG0zUjwDBT 9dzmVscu2b_IdlaUDc0A4UGIa4GcYPY7YiD1Q98yENxpZw uUcuweA3Z7gIiiyTC6fxwk1FjZZGGByoM34mIC3L6kD3YmFbkQ5y15yDXL_DzAHtnd280sSKNemQYI VpRy19KYNDUmOoisCQboZLT7ngT-GzkAAEQ3F5Mh2oIiiKAb J DQw7Y_0VSYBh4DJ9j8Uj5ZI1Rvr9FIS_ZR4IfwYA1LSr0 FCtSTs=

Remove setupimgburn_2_5_8_0.exe - Powered by Reason Core Security