titancsetup_eb0200.exe

Playtech PLC

The application titancsetup_eb0200.exe, “Titan Casino Installer” by Playtech PLC has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. The file has been seen being downloaded from worldswiki.com and multiple other hosts.
Publisher:
Titan Casino  (signed by Playtech PLC)

Product:
Titan Casino

Description:
Titan Casino Installer

Version:
1.1.1.28

MD5:
a7a4cced9596be274ccf54ff087c7df3

SHA-1:
151ece558d19f475ce92dd21311a9151a46d63d5

SHA-256:
06a9ff0f3e0c463dbd0394bff7a770a6c8ab06a4e116575822903ba7548c9c4e

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
11/24/2024 3:57:30 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Adware.Agent-6597
0.98/21411

IKARUS anti.virus
PUA.Plush
t3scan.1.7.5.0

Reason Heuristics
PUP.Crossrider.PlaytechPLC.Installer.Meta (M)
15.12.30.16

File size:
939.1 KB (961,680 bytes)

Copyright:
Copyright 2014

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\titancsetup_eb0200.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/20/2014 1:00:00 AM

Valid to:
1/16/2015 12:59:59 AM

Subject:
CN=Playtech PLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Playtech PLC, L=Douglas, S=IM, C=IM

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
764E6DB88B018BFEBD8F7B533DC3A6D3

File PE Metadata
Compilation timestamp:
12/4/2012 2:55:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
24576:ZYc+xZV+eAgqcuLsEbdSZ+PrvDUgqrV1WWtcFk:Z4V8gbuLhbdU+zggnWtc+

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Code size:
34.5 KB (35,328 bytes)

The file titancsetup_eb0200.exe has been seen being distributed by the following 2 URLs.

http://worldswiki.com/.../?c=titancasino&lg=lv

Remove titancsetup_eb0200.exe - Powered by Reason Core Security