testfakt.exe

Fakt

Fakt Dystrybucja Sp. z o.o.

The application testfakt.exe, “Fakt Setup ” by Fakt Dystrybucja Sp. z o.o has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.fakt.com.pl.
Publisher:
Fakt Dystrybucja Sp. z o.o.   (signed by Fakt Dystrybucja Sp. z o.o.)

Product:
Fakt

Description:
Fakt Setup

Version:
2015.09.1.0

MD5:
8baffa29064faff25418a1809cd6514a

SHA-1:
a1c1ef56cf42e4ee6b187376d34c1f5ed079df5c

SHA-256:
20e6f73e0ddbbfd5b462f06302442c83aaef3074822526b60bdb5305562f0db9

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/15/2024 11:10:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.IM (L)
17.1.30.20

File size:
17.7 MB (18,528,872 bytes)

Product version:
2015.09a

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\testfakt.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
4/17/2014 2:00:00 AM

Valid to:
4/16/2016 2:00:00 AM

Subject:
E=serwis@fakt.com.pl, CN=Fakt Dystrybucja Sp. z o.o., O=Fakt Dystrybucja Sp. z o.o., C=PL

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
66AE9F337C2A59043DAC9700E598AE32

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file testfakt.exe has been seen being distributed by the following URL.

http://www.fakt.com.pl/.../testfakt.exe

Remove testfakt.exe - Powered by Reason Core Security