stremio_setup.exe

Tihakote

Agile Delivery (Alpha Criteria Ltd.)

The application stremio_setup.exe, “Tihakote Setup ” by Agile Delivery (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.deliverybundlehosting.com and multiple other hosts.
Publisher:
Boforodif   (signed by Agile Delivery (Alpha Criteria Ltd.))

Product:
Tihakote

Description:
Tihakote Setup

MD5:
10ae30f503747e3dfbe09397641510ca

SHA-1:
59d680fd894787b54ab4953b59e23d95837f4963

SHA-256:
9e54fd185bb08ac96b03eca9aff8516a63e7b0efb7f4919651525e4686ee5f8d

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/15/2024 10:40:52 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC.Installer (M)
16.4.13.16

File size:
1.1 MB (1,125,376 bytes)

Product version:
2.0

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\stremio_setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 10:23:29 AM

Valid to:
9/2/2016 7:29:04 AM

Subject:
CN=Agile Delivery (Alpha Criteria Ltd.), O=Agile Delivery (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112167FD2CE27007C69C69FE47CED0A20713

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ybJCG8+SKRGZ7be4vZMheGk24gkLOyal0aJPJa/s8Y:y9l8+SXptZM8G8gkLRaBJPJa/m

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file stremio_setup.exe has been seen being distributed by the following 2 URLs.

http://www.deliverybundlehosting.com/c?x=R10gpw0geQmjUFGScVApszKf3 esywyZqo7MS5nz/Nw=&c=3v4org v7qIB8zoyH4Ot9q1XFUwUIbbhLBFrC0e8LzIN5wupW5t/u3DurLknLBGWtfVbdVfMj5VETuaC5B23NSho3WaH0uT5o8KYjabzyqplMUexKULBNaPENu5Dv4rL&downloadAs=Stremio_Setup.exe&fallback_url=http://.../Stremio 3.5.10.exe

Remove stremio_setup.exe - Powered by Reason Core Security