update_installer.exe

Setup

DOUBLE OPT MEDIA PARTNERS LLC

The application update_installer.exe, “Setup Application” by DOUBLE OPT MEDIA PARTNERS has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the Setup Factory installer. The file has been seen being downloaded from r.browsoftdl.com and multiple other hosts.
Publisher:
DOUBLE OPT MEDIA PARTNERS LLC  (signed and verified)

Product:
Setup

Description:
Setup Application

Version:
1.0.4.0

MD5:
697225399a3e1e4184711dd57782e880

SHA-1:
a8087a0d1e219a63b975b8986cee7ce41d3a4d96

SHA-256:
197220d72e42817528c309a37b67d60ed80e0b66de99e4bfac07324f10fc97fe

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
12/25/2024 1:23:19 AM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM41.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.DoubleOpt Media
15.1.26.11

Trend Micro House Call
Suspicious_GEN.F47V1115
7.2.342

Zillya! Antivirus
Trojan.CoinMiner.Win32.389
2.0.0.2000

File size:
1.7 MB (1,802,848 bytes)

Product version:
1.0.4.0

Copyright:
Double Opt Media Copyright ?1992-2012 Double Opt Media

Trademarks:
Double Opt Media is a trademark of Double Opt Media

Original file name:
suf_launch.exe

File type:
Executable application (Win32 EXE)

Installer:
Setup Factory

Language:
English (United States)

Common path:
C:\users\{user}\downloads\update_installer.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
10/9/2014 8:00:00 PM

Valid to:
12/12/2017 7:00:00 AM

Subject:
CN=DOUBLE OPT MEDIA PARTNERS LLC, O=DOUBLE OPT MEDIA PARTNERS LLC, L=Wilmington, S=Delaware, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0289DEB63998EB06A29C8E7F34C73E75

File PE Metadata
Compilation timestamp:
12/16/2011 2:06:40 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:WsY+7u5ZCn0kDb14A9hCk0ydWezd6uIccm:eVffkDbJ9Dvd6uxcm

Entry address:
0x29E1

Entry point:
E8, A6, 1D, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 56, 57, 33, F6, BF, C8, AB, 40, 00, 83, 3C, F5, 54, A0, 40, 00, 01, 75, 1D, 8D, 04, F5, 50, A0, 40, 00, 89, 38, 68, A0, 0F, 00, 00, FF, 30, 83, C7, 18, FF, 15, C0, 70, 40, 00, 85, C0, 74, 0C, 46, 83, FE, 24, 7C, D3, 33, C0, 40, 5F, 5E, C3, 83, 24, F5, 50, A0, 40, 00, 00, 33, C0, EB, F1, 8B, FF, 53, 8B, 1D, C4, 70, 40, 00, 56, BE, 50, A0, 40, 00, 57, 8B, 3E, 85, FF, 74, 13, 83, 7E, 04, 01, 74, 0D, 57, FF, D3, 57, E8, 18, FD, FF, FF, 83, 26, 00, 59, 83, C6, 08...
 
[+]

Entropy:
7.7789  (probably packed)

Code size:
22 KB (22,528 bytes)

The file update_installer.exe has been seen being distributed by the following 45 URLs.

http://r.browsoftdl.com/clk?partner=36&subid_1=2nLP4NeyK7MlEKUVPeGMCLX0acAytlrwAvXjrEyr-5QzA0WT15vgKS4lKcZKSXYgty8gKyemXZ_fwsagFfcgHQW3LxlYtc8tS4Ihj027lRWl03Cpn9tF9sM4z2uRATn_7H2TiEkvWzahYS3fu-AiVrNWpuceAYC4bLvSn2nsuIiwyqkKDELn0k0T-IAAS3IT8iXLYNY02adob-HRJs43SgN7IpHxZrf5_vnVC3e_hiIvoUoNDaNBxo_iuDLXEdWl8mV2auADcx9q0LvOKWOLRlftSmbiQTBmF3PFYKr7mdnP1d8ZTdgih8mijy2H7zYKc_FDrbC0tNOoRx96WKhENqvvA63Zf6VwGX2f3xMBXXl6faz4x68fDxNPjz405Q6QaIalpjOfh69gJTSAydl4rDToLUEegqWJs0ai8BkKsizF7xIw8jfTSJB7jfuArbNC9uxti1yEqx3cm4byaKlUYOKQXo61HFKndM7ihX9ifhcvUwDM8v9T&subid_2=&subid_3=video_2

http://r.browsoftdl.com/clk?partner=36&subid_1=nym1CKiz5avz2b_0cxACGJTltMTWgsjQYiINMTA3Ljc3LjY4LjEyMSgBMIH-saUF&subid_2=&subid_3=video_2

http://r.browsoftdl.com/clk?partner=36&subid_1=Nnf45d0zVomXgKsc9Sqak2EZNnJtUA5ZCUo4k62s7zu84Kpxj3Q2oXXE1SOJWcqmTo2YDdYjUqZyWFGj3Lu0fLcyJfmyFxB4qKzfJJau0KwqxF1K8UNuHLt-ispYyLcXHBOn4ZAxug1rec3RruiguMz-GKDKH8d68WdxviH7hPhEnakaVePb7_69gt8dBYAY-AMYueqi49FUlN7X_Ybqmfq5MKv4RWyoVBzE4_VFEyzECjohqco_5szTkOJcHJ3ycWQ90fEm-JH5HEx5vCQArS5A_1xdR6VclQzCm9wl6O-RBwXwGS6QvgcOcjJPGCT0TlxTizay4qZh8uf9D3y-Ugbzmwr_P7XZsKul7RZoGDBAdR2rGSOvqbzsW09A3AnoTeq9RLkZ1EaXGLvfbqqf-BgFVJgP9vmWGyBxmyil-zVYWEHlJIQL8DzXVI5MxLuUVumpu7YwFXTCHkxBgupFYSOm81cAPA&subid_2=&subid_3=video_2

http://r.browsoftdl.com/clk?partner=36&subid_1=Ry9a8K7UwDOWTlfHHu0viCl9BF-KCJa637aofv3uYhFKH2h-NCIVVW_UeDaIMtk0dbPniA2dSoUsZ_q3ZlWiWLKMloHBgjGL6z4D70cW1eCHA-MD6QXh9b_bTo-kiEdZVGFqtBTL1aYykN2sJEPrui1_UlJpQtSJpxpmUK0ASQaIwIqB0Tp5LhWs39QyL_RfvwPJVW_3JxW6g0k1wDW2FprLLrMLonxBaMDAKcQDdGY9EWlf7cc5h0rzZ9vPsrOtzgbKUYWHmABe2BQNm1t2bu5IiJn9SkLzkHeocJUjr_EAZFQOVK9H1RU_ESWeuROUxg5VHJkuNLZYHPgSuI5TMjOUWj-g6AJz5eOKGAZ_28MJkBo5JoLfEegs7BGGG_v0ZUuTi2IupUWB4IauQ-V7SbF24YMGSX9g8T-MoOKvubCGqpjv39TaPBYJK_ywmkJO77s&subid_2=&subid_3=video_2

http://r.browsoftdl.com/clk?partner=36&subid_1=FrPLV_g5LU6Y4c2cfAIFP4eQRcjnvyXow5mp4aE3YZO0UZRqJ5ieMknaqqnNtk3VF4iGHmqJQI29s6PGsYhmDDFQAjW8CR-prriSP7yTiSIRLri0TmXtxuXkyqOrfcexchS6Zn6fuwOK5rHHh89Q1YGqfa5Ob3X1aCeYf8Uu9I4kxsrS5zxSSs1Axg8V6oDWAVpHqL6slrJhuyae2aLzjqMWPELf5ISeQs-6XxkWs7LfzR2Jb39OA_OoYaEY9VVbPHJ6p5cm43E_lfo1G7rYbGFarsaXmzTYdV9zIqiQoyIPZ38YGOxKlfPn_rA103yBPsgfSU5uOeu7hta7pVA9T1WBVt5Ch0DakEfkXWGmeFUkneZoa3MlFt5Gx_yrD1fk1fgbXCluScQYnLc-Z2d-VoEP8Oki-i43mfsF2jQkpki-4hZBZICRBdHIGJfUjEQqruqh1EE1Lcg1QArU5XjAh-Q&subid_2=&subid_3=video_2

http://r.browserdownloadsoft.com/clk?partner=36&subid_1=nym1CLjz7e_o-suwVRACGMu_7uu549zNWCIONzQuMTA0LjEzNC4xODgoATCuwJGkBQ..&subid_2=&subid_3=video_2

http://r.browsoftdl.com/clk?partner=36&subid_1=j34dU5FxPiPwSVdvvD06F8h7Vw80vpjVeojSGBDuliPSub7fWKFBLveRBOpANeXuXfC2y85zqRt4lH4W-chvvTpuzH9GVeBlGpd1PlJ-No_xFFdQRKIT05AEhQ9Wx0IoPtUqoVRmFEb-cKohXIanBUF_gbj2V0soIrm8_mclbCLrvKU-bGIG3IQgJNU7yuV94Zhfzcpyc9EA91YOn4wokhK4YynOR4xWxT7KZzlR--6ir-88SOa83NR3giCRbSggE52ILaai_r7gvlYlBvslTVvpdk8bBiHtSE9VtSC4tfq273WZoty5P749-w2ImDbObymxqsFpSrE68TIC9wg9yQ9LLV7rI05Sy-lFYzINcN5X2SAnWrVMWwZvmuO9QxFzppv6DGUyD28SAvj5hoiTKOcJQIeLAUPnK9_v6MCzh8MgEXxBIDDmGlc2QTByOs9PcJRoimq96Dq2AdE08Ch0K2yY77w&subid_2=&subid_3=video_2

http://r.browserdownloadsoft.com/clk?partner=36&subid_1=nym1CODMkPXuvs6iOhACGKna0bfLt_6CbiINOTguMTc5LjE4My40NigBMJ7mnKUF&subid_2=&subid_3=video_2

http://r.browserdownloadsoft.com/clk?partner=36&subid_1=lax1CJSC6pGllKn1SRACGM3ii4PF3baBICIONzEuMjExLjEzMS4yMDkoATChl9qjBQ..&subid_2=&subid_3=video_2

http://r.browsoftdl.com/clk?partner=36&subid_1=JER45Y7-LY4W2a1mmQHZyq210QHoKlde4dhKIgZLDjVWPCjheauVR2E9WFS25IEUuZg8pUsJJycmosOldNxRtegpRwqqD9BKJ-9Z6xtvd0p3yzYpBnXtvXkubKUvCJ2QMd7sWO6o09IdrAW8HkWNIxcHdIqJPNJrKCaVYDp5QwT6ys7kj_sfuP3r-xqTEl2JQ6xkyS69geH58v8tabvOF59YxZC_Pmr9gbA-xEBUOqQuUVT_mpz9dxAdQV9b66Ccg6eLSD4YJbRQVQqD18hPh47Y-jkOuvBrWldNG_wjfStGlWb1LjYQNRuB_mtzenYg44T8bgWCv7A3syuJ8SfyVOkRboebLf9MXsAFomVq0Q-g45QYknZmz-59QGD00HW-weoW93R-CpwlhVmDnsn1dHHyX1nx5i5E1_Uv3Xm2MMF_qA6xcNfgVSiT22CQh8kJugyNZ3uQ54LJSu5bap4o74b0nWIZgqV6kd-ERrMKkUVD0ZUCJHWMNKxq&subid_2=&subid_3=video_2

http://r.browserdownloadsoft.com/clk?partner=36&subid_1=nym1CPvMkPzl68ekKxACGOv-iPfM0OznJyIMMjMuMTI2LjYzLjU4KAEwhJyMpAU.&subid_2=&subid_3=video_2

Latest 30 of 45 download URLs

Remove update_installer.exe - Powered by Reason Core Security