setupvoipbuster.exe

VoipBuster

Finarea SA

The application setupvoipbuster.exe, “VoipBuster Setup ” by Finarea SA has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.voipbuster.com.
Publisher:
Finarea S.A. Switzerland   (signed by Finarea SA)

Product:
VoipBuster

Description:
VoipBuster Setup

MD5:
5a4c8723d8a51a7f92e2495f0dd58919

SHA-1:
6ba1cf43c7a812f14d2ddf2753e5cced19133c47

SHA-256:
bd098878b89ea3f7839992c7cac267192bf4673e7982a25e95df3fa2baa3d2f9

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/16/2024 2:31:33 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.31.22

File size:
6.3 MB (6,639,176 bytes)

Product version:
4.14 build 745

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\setupvoipbuster.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/8/2011 1:00:00 AM

Valid to:
12/14/2014 12:59:59 AM

Subject:
CN=Finarea SA, OU=VOIP, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Finarea SA, L=Lugano, S=Ticino, C=CH

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
53888339B46AEA14F612344B8D789BD5

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file setupvoipbuster.exe has been seen being distributed by the following URL.

http://www.voipbuster.com/.../get_from_mirror

Remove setupvoipbuster.exe - Powered by Reason Core Security