uninstall.exe

IronSource Ltd

The application uninstall.exe by IronSource has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
IronSource Ltd  (signed and verified)

MD5:
48279256105b47ba77d000ca3b7d3a1e

SHA-1:
69b0207bfac243e5fc969c471ebb36b05483bbc7

SHA-256:
c61e58f4ddfd0c072b12deeb8a02739c202d2cc76f6da1ca4cb77f933ba04f20

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 7:43:38 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ironSource (M)
17.3.14.9

File size:
1.1 MB (1,107,336 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\uninstall.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/8/2011 1:00:00 AM

Valid to:
11/8/2012 12:59:59 AM

Subject:
CN=IronSource Ltd, O=IronSource Ltd, STREET=Namal 36 suit 1, L=Tel Aviv-Yafo, S=IL, PostalCode=68033, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008E236034501AEA96AE96F0B0FD227271

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xC1DC6

Entry point:
55, 8B, EC, 83, C4, F0, B8, 8A, 92, 4D, 00, E8, 1E, EC, FF, FF, 13, 64, 01, 65, EF, 13, DF, 62, 7D, 4E, 4E, E7, 9F, 09, 59, 5A, A2, 27, 25, E5, 8A, 3D, CD, A0, 28, 18, C6, 0F, 2A, 5C, 20, 33, D1, 26, 5E, 76, FC, 7D, D6, 17, A4, F3, AB, E2, 14, E4, EF, 73, 5E, 07, 7B, 2E, F1, 5A, 81, B8, 39, A7, F1, B4, B5, 0B, 2C, D8, 01, 4B, A2, D5, 9A, F8, 5A, 8C, 7B, 8E, 7C, 83, C4, 08, 55, AC, 1A, C2, 80, DD, 5F, 86, 21, 97, 02, 09, 4E, E9, 06, 59, 34, AC, 62, FB, 7A, 49, 89, A9, F5, CE, 17, EE, BA, 10, F8, 2D, 0F, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
787 KB (805,888 bytes)

Remove uninstall.exe - Powered by Reason Core Security