webinstaller.exe

JDownloader

AppWork GmbH

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application webinstaller.exe, “JDownloader Setup for Windows” by AppWork GmbH has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the installCore installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from installer.jdownloader.org. While running, it connects to the Internet address installer.jdownloader.org on port 80 using the HTTP protocol.
Publisher:
AppWork GmbH  (signed and verified)

Product:
JDownloader

Description:
JDownloader Setup for Windows

Version:
2.0.0.1

MD5:
11dcaaa7c7371252c739b205cb4c1313

SHA-1:
6cdff4382794d3a81f975df13e7af12b0678e53c

SHA-256:
beeb6321438dab849034ce3a7f9562d41fb268f9fb7e43eb60f6b85b7735c2f0

Scanner detections:
3 / 68

Status:
Potentially unwanted

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/27/2024 12:52:30 AM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Trojan.11366268
0.98/21411

Reason Heuristics
PUP.Installer.AppWorkGmbH.M
14.7.28.0

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

File size:
72.6 KB (74,336 bytes)

Product version:
2.0.0.1

Copyright:
AppWork GmbH

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Nullsoft Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\webinstaller.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/31/2014 9:51:29 AM

Valid to:
4/1/2015 9:00:41 AM

Subject:
E=e-mail@appwork.org, CN=AppWork GmbH, O=AppWork GmbH, L=Fuerth, S=Bayern, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11218C489DBD3BC8AF35CDB519BA450DC59A

File PE Metadata
Compilation timestamp:
12/25/2013 12:01:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:DwDJZGrZopISbAoR8BXJXQ9R9lFBtRThFTSYm3MJEpy5:kDJ0rZo6StCBXJI7BtNp5l

Entry address:
0x3219

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 98, 37, 42, 00, E8, AD, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, A0, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, E4, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 57, 2A, 00, 00, FF, 15, B0, 70, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 45, 2A...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file webinstaller.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to installer.jdownloader.org  (85.131.130.148:80)

Remove webinstaller.exe - Powered by Reason Core Security