snapchat_setup-120847569.exe

Fried Chicken Interactive

The application snapchat_setup-120847569.exe by Fried Chicken Interactive has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from files4.downloadnet1004.com and multiple other hosts.
Publisher:
Fried Chicken Interactive  (signed and verified)

Product:
Fried Chicken Interactive

Version:
57.3.5.6664

MD5:
a4247477902565fc3fa481a6e60c72fb

SHA-1:
76cf99896078ecac2b4d49fe0301b1c3ea458178

SHA-256:
8fd743b3ce0070c6a0c0fb33995b2cd8016a867ea29e27d5b7a4e827776f26b9

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 12:22:55 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Win32.Trojan.WisdomEyes.151026.9950
4.0.3.1644

ESET NOD32
Win32/DownloadAdmin.Q potentially unwanted (variant)
10.13282

IKARUS anti.virus
PUA.DownloadAdmin
t3scan.2.0.9.0

Qihoo 360 Security
HEUR/QVM10.1.0000.Malware.Gen
1.0.0.1120

Reason Heuristics
PUP.DownloadAdmin (M)
16.4.4.21

Rising Antivirus
PE:Trojan.DownloadAdmin!1.A4A7 [F]
23.00.65.16402

Sophos
Download Admin (PUA)
4.98

Trend Micro House Call
PUA_DOWNADMIN.SM
7.2.95

File size:
894 KB (915,496 bytes)

Product version:
57.3.5.6664

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\snapchat_setup-120847569.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
3/8/2016 5:13:39 PM

Valid to:
3/8/2017 5:13:39 PM

Subject:
CN=Fried Chicken Interactive, O=Fried Chicken Interactive, L=San Francisco, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
1E418FCF3E719CC2

File PE Metadata
Compilation timestamp:
4/22/2015 10:06:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:acJIKEUlX4peA4klTx1NK/BjdANnMKtcSZa67hXy6:gKdipeAVlTx1exdItcSBXy6

Entry address:
0x3FCB

Entry point:
E8, 90, A3, 00, 00, E9, B0, 9B, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, C0, 17, 4C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, EC, 17, 4C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, C0, 10, 4C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, 84, 10, 4C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, 6C, 18, 4C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, 30, 18, 4C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 81, EC, 18, 02, 00, 00, 53, 8B, 9C, 24, 20...
 
[+]

Entropy:
7.9650  (probably packed)

Code size:
56.5 KB (57,856 bytes)

The file snapchat_setup-120847569.exe has been seen being distributed by the following 4 URLs.

Remove snapchat_setup-120847569.exe - Powered by Reason Core Security