webinstaller.exe

JDownloader

AppWork GmbH

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application webinstaller.exe, “JDownloader Setup for Windows” by AppWork GmbH has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts. While running, it connects to the Internet address installer.jdownloader.org on port 80 using the HTTP protocol.
Publisher:
AppWork GmbH  (signed and verified)

Product:
JDownloader

Description:
JDownloader Setup for Windows

Version:
2.0.0.2

MD5:
6a72c470371b4ca7777161f8f015beeb

SHA-1:
81edc1a47e42fed4ee063c8947d6f70cef95ba9f

SHA-256:
830150b51a97d073d19b5e399bc132c3e96483dd95649a848401a78aaf4d1fcf

Scanner detections:
3 / 68

Status:
Potentially unwanted

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/27/2024 12:44:28 AM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Trojan.11366268
0.98/21411

Reason Heuristics
PUP.Installer.AppWorkGmbH.M
14.7.28.0

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.0

File size:
74.7 KB (76,456 bytes)

Product version:
2.0.0.2

Copyright:
AppWork GmbH

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Nullsoft Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\webinstaller.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/31/2014 11:51:29 AM

Valid to:
4/1/2015 11:00:41 AM

Subject:
E=e-mail@appwork.org, CN=AppWork GmbH, O=AppWork GmbH, L=Fuerth, S=Bayern, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11218C489DBD3BC8AF35CDB519BA450DC59A

File PE Metadata
Compilation timestamp:
12/25/2013 2:01:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:mwDJZGrZopISbAoR8BXJXc9R9lFBtRThFTb0B9htz1Y:3DJ0rZo6StCBXJU7BtNA+

Entry address:
0x3219

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 98, 37, 42, 00, E8, AD, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, A0, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, E4, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 57, 2A, 00, 00, FF, 15, B0, 70, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 45, 2A...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file webinstaller.exe has been seen being distributed by the following 50 URLs.

http://dw.uptodown.com/dwn/UHdCBhYRLQMS54-Xm3nKy_1ldEvKAjhZrf_TfoBcFJcU-PyTVOSFEakZnwlXT3o7O3Z1ZRA8dHDcJY5PidJ-vLElnKAwNuA72XHI1_6OI1YmWOLURY7IwrQ5EFTl3zaS/GxVXodHyfv_kWRkm4cLI_ot2Jf8w316PHOT9NJnSZGwQV5Nm4gzMKvw9UaXbfb1ZREz_qENuMBWlTd5ERsPtT5QwdrQzpau9QGkLTC__FEORIRPSpShJvYATMZ6f0PhE/.../

http://dw.uptodown.com/dwn/cE4k6mjc2mN9ssIoLjd7d2TLTzMd0AaZ-TTVjNFz0VwDNJkqMznOmSaHfyy-O5aImGvIOyz1s1S5XbcAh0nhyVRTGszRKb7cPlfNVymnblszBc3BSugBRUpqa5bTWYR2/oRl5ASKKWqODJVz1THi3f2UrO5E70hMmW2sVnMS2SfkRR7B5NTBmQMvJqXEZx4hw8C7NP7WOxttnXTrf2zVzp5WQ9djMHB0z74MqXz4lwGo0R-ujXbUcMDgFdbsBXvKA/QkcZOasjux8o1GKCgwrGEAGLkMeMVm-LR_LwcazST8kjkbHAHqZ9fpmXvP0KUCbqdhu4ye-pDDi2z5RXDf5diYSIaLBK8Brb7d31JvksbXrF2op8ZIEyzO6A1XbgvWlo/.../

http://dw.uptodown.com/dwn/PNcdGv0yljZsIHSaKIfDSgCE01tRnV72TofY-TWHZ7Jye8y-l-SEhVSLx1SJxv97zIXxCTQQMMKDK0aAjokUGa1qRpX6DdJATwo1WhnjFLOrMYz-4iVALtGmW4PXBa31/RXVtOgFcpCnCAlx4xNlnPK06f5AjWV2XW_lUuXwyDGHMAs7cYJMfYPWpfCKZ8ThTXmdk3AGF9hKYZcoE5igN6BNobqJ2VSQGuUIMfzG_dXXxLk095hPGPAHwmgLlWmfE/HejzUlOlIBaYxDbbahjcUcwyCOFRzrlAPhFVkT5KbdMjVDhHLYm4RZyk7hxqXWAqY5wcyx9KfcrU8tGXvd3mAw47aoWnWpxy0ekqr76-PAF1dJRaRs7CA_r3-wtD8uav/.../

http://dw.uptodown.com/dwn/jJjZtwffUUiER81BAa2jfEdY3QvK8BHqdAEcgcTmhODm2qtgM1kkQFoCdxmROXWDR4bh2Kc4-1E-QgooFr7z94etJJycRrvzEhu4Qh2iYArAFfXTJI_v89FbejiIRvsE/-Rk9yE6Wa-PfaBHmvYJqjz36Ek_ABEM7uKVlsoqPOE1Ro5E9Ai9Boim_zNr1B6hj33jdCxinjrf9WYEmdt7oaWMrkTyP4ZCjOAlyy8qXFrBR-B_hh39pzau71y9vx7Z7/i741bg-YSKByg7ewnuLUqnz96SMbcCqQ8ANOTwK9nHLGY5n0tl1xv0DQ6d7drT2a50AxTyIs-_GoAmpFW8K-H47LxugeN06fW4XV11dli5fxmzqLXJwdbPnSvjd_lYvo/.../

http://dw.uptodown.com/dwn/lt9ErMXSrlM3uaAvmLL8cYuRKH4FceunlAOhf0fcEyN7YFJ-VHwVYegD-wODpFZeHkF4fkWng-QFJj3tPRXf5kWbRie-210kKmVKnggBymbLy1j5tnBLH2S6YS-6PJL-/QScyYIIXLUfB8w-NiN4kupfwm9vu4-hxR0L4dF6lkNqfN2-WtNFBXULV7N_cIWg2cH35rfwo2pmFhQFNg3TTafZyMklPeDFcEHd5w5pfIK2ZrOdVzvX72NPa2IrlkHpQ/jM6xG4RB-LlsDNbaoW5kv-QzTJwkt9qYFs3YpZquRA1hW74_HICyyy7NnvJGIqpMqm8BodKdVEpEbtaGUTxWfH9ogVcFTACe0KvZ63eLH93EQ71KhsRV681WWw42tCCr/.../

http://dw.uptodown.com/dwn/U2F_64-CqkhhD7X-NH1vG0V5yHKO0f1EwdJf3dNc122AZpKC2UiNISKx4-O2-tcnX--_Dp6kFAr1CM3dP_0p9ewb7ooSBTpTMw2_4mGGjKzRIHFfHVfLQ90UJv73hoay/cL4y6obLcMASmw4HmSx_c3zXbt-Jyk2q2rLNBWWz0bBqDfbLpmSOcxLwLxk0a4Q6iTHxTj5ZWnkPs7F-1J5N3GFR-ADnghFz3_Z2-WKrqBo5IBqHdzYeEJkz6ZHuS69T/xbGbnGmCV_EhDKRfC6yusQZmZegvuFHY1bGUssn7Nx63emNCObHmCKGucNIB9J4WyNQb61NfiFawFosVwN7Rk6ok5Of80wWCrSsMVyujxNgQj7HI6dXohy7D5a0T2woD/.../

http://dw.uptodown.com/dwn/c1JwGBAeTf2masvCo3IaoMG-NeW3G53iUFgsifauESlSxUe1kI4QkYsNMVn6TP_0e3IGWMtYCmbBSxUU9AsXpgbzNywzTG19JYC2zSI8Qx7t63EcPogWzMKToD2GdkNR/19hvtgrlPKrO4-DHw6u30C63B9pbLxkVugK0CqOBWBEuKXnwiODMDzrTXLV0scGBMD18L0mIO0aV41A30vm1JY7YEb490f3Qw3K7kRfWCiHgoYe84zyYjnWcyOWeV2BH/AEtzM_BBstyXgbCsiIzlgVybXPr9c8y3MYNLRDrng-cUSCLEWc29sZ8aCxdLcjyn6EG56eZ9Fpvqj7tDGc-nJ3NPBgv2rqHvYOdJZ2fkxy1kNAVjkwXNAc1lRduyIHrL/.../

http://dw.it.uptodown.com/dl/1442457980/.../jdownloader-0-9-581-es-en-br-fr-de-it-cn-ar-ru-nl-pl-cz-dk-gr-cat-win.exe

http://dw.uptodown.com/dwn/b7AHg-0P76Fs4u4OuSIXsg3eHh3QnJQjUJpJonaSaMoTH6M6p6ESpcZV3dq1xaIT4PAj4Zp4UbmLLWHut_g_zIRNVdJpl1Z8LV-Mwo40Ahp10Z7efMSd7pE9zsjAUWCA/ukXUm0J3yLqUyUXEeBwcNzQGbOlhyMAIbpolgcR3XSDvlcr1alBRojAd7q96As7DsGU4QFPsEJYxeLojWK6gbLOdgW08kybx-g6IIcE2_0LzFC32V7C-KtrlvChsVxon/QfrqO5ZtHu5w4iAMYzducWW-aYzEpYisnlIpEYC-uop1nLhbPmQHjK1QuqlHrzh0o9uYQsPBRZ-H1BF_mVAQLXBclu5ukDVoILGgCqtANCVxvI-_lEjRWwAfQvTrzgTP/.../

http://dw.uptodown.com/dwn/1iDfw1dXJfGHa2kE2147y0cPRBXgZMnwYdcmSetlokMgNFXTD66DhZgSWRvfFGM4DqldTgNZs4Kj2V2tj9zAXsZGtuqgQ-ABt-1u955vkwxANKwxF1Cj4Es94FcRLBh0/4uo1E-oI2oI1NFpYkWUCxtEywnCKOTzEq54mmjcudJLCP8qKwnAdMap9TZ9uIubKH-MwbZMcUvy3kId16sgqnzv7zdPrAq9WHoOLar6C0RVUJu6aZYkeKL0Q7IgHXfoK/-jZj09COQ4juvEhgeBlQmI-zF_BFWdp8unNnO63-Bubqjo-x_xbB-QxAP1oj3L_aDJcOeHZRKl5hmjRVJlaILnMwnqd49bnWqPt_WjM5M4Aw2VD50VXQN73uOuj30HTb/.../

http://dw.uptodown.com/dwn/Vpabdzdh5C0del_KZfaisYzgmcnzkVAcsi_03pufTt7p1WPgO5XWaQCVQBmpJrRqt0iTFxxDOaUy2Gjc0eczWOASr0y2eNSJiPCRTGAht-RAlp1Cs3grXxM8y0bnKl0K/51p1V3HDmpvrBZEtx64Rr4H86krIz_oT1OWiJCVSYi-knlGOHiXBBqSgShJRqL7cNWhY-XEsobhzds6ZEne16GxD5e4jEOmEVfD9eZ5eSfBwiANYER3tSg-g_PyCQZUn/7QZhnxYEuhjS-ch4wfUM0CXjqBPWFwOwmGMwpsQuz3gfyH6Im6OrLT9RA9pyzRRyE6sFPq5taeuy3XVo3N1Ym3pYEwQdmfRSiwm7Qis0iuCcbAKiqbKI-eFyH2csM7HA/.../

http://dw.uptodown.com/dl/1439524970/.../jdownloader-0-9-581-es-en-br-fr-de-it-cn-ar-ru-nl-pl-cz-dk-gr-cat-win.exe

http://dw.uptodown.com/dwn/pwgN9idPvu8oKYwVvUJQIP2qe8biG074gZngH3nYjri3u3fyeuwOT_fheYn7kJWuKwfwOJqYDvNllBNhQUFGoPW5ClSQBuACr5sY0nL0phbV2RRkLNk1cEvD1X8ITBHk/43TLOV9wwVZnByhWh_9L0VPSMYsCFjGg4zsMcaBB_5oyXKWf8om4cEdzkjr79qHbhhnC-0w4LTDEt_c3bnqUN6McAUeWacNpqb_bBu5BiWTdqKClX2WwkfHJ-L24kntd/rSh9Y9S8WBVusJQLA3HMOkdYwgz1wy4x-OOFJ0LLt3Coa4sZp59vA_j3Q-cJj0K-8v_QGCMcIiX2_MMjPx5b1RfvZPZSzMsOTSM-roPkMrEm6LPWyO2G0KM1Ys18kiNP/.../

http://dw.fr.uptodown.com/dl/1443112375/.../jdownloader-0-9-581-es-en-br-fr-de-it-cn-ar-ru-nl-pl-cz-dk-gr-cat-win.exe

https://dw.uptodown.com/dwn/TeTZYscG2hJ5ney86I6YXmDqbSMmPHdbckc5czb494rIsCzSn_0KVYnmE_zi4FwwZYAMle2UKkWQzTjxmAnjWT-V7bVd_4nGiUiCUa_RVD9xLfJrIusx2HJMidKidP1y/CFh9iuBvmDUc1D8CDkymqBFxq1I3eIjOQq8mn3lH0rkg1T-4ZRM0FnIvsFpCI9dkaPgLH3rcXSQQ2hLCZzsiASDJA1Cf4QdM3OdrDrU4xCp5eoV8GSBS7Av84agQZUak/Oiwk2TUd__WraQPG1cPv_OPBnF3rU3DOoGY01xioWNmrrtVpKuIgTSsUBD8Amp7mV_IiSkqjope4eYBjqGnAQTHCQlZqDO45h15cVwNjawDIJu5WOBL6y-9P__VUCw4M/.../

http://dw.uptodown.com/dwn/TDNJQAKY8x_jSZBekeZ1hd3zy7CzOS5fqVuYD3FRXkucTHg3LDRhKVOokW-iaSiprpJub2cDElOXEKFmvVy-JFawYURdbE3b_6QEJ9cRgR5VennCBaUHpO3hy8Dg8riy/p-CKFusHibcZxp1VPF4vTZG9_f_jGTjP3SJOmLeM16ADjoM-WYjlztMUg0YtMvXfr5Zm2y7DUsIoQkF6a8cbSBBr5dVpMzNx5nn666lUgIt2bJTnmGg78nKBmutrtTyW/M-AjSxrhhFuJ1hZe9A_RV8v2kAfZyzB8zmZJG0CaCNWNCdFXdt48XAnfl8Ar3yfK5xgUJyCxca8EE7rb62bPZDVs-qBkVm6lI-7wzhuK7DeHMiukOOa8fqiBR4kwEfdo/.../

http://dw.uptodown.com/dwn/xLK45j8qTzvMRvY-oHOmyocJ-xBKX5Q4oHsv7TowMJ-XZIQKtn9KSOAMRyev9QsBcRTfNo4cxWqLO_P_as8LItIvoryQwnH_dGfUGg0P-Y6xPvMqiSXBZRTVeB74sUy1/QdabdDPM3ijbH4qrQEIxNJQFZu-_iDDf1zPaOaYPQVQDOP99FHU6F1U2zaZbt0upt2cKComO68gxXP-uAZmUmcEHNFguDpO0QM4CsuYTn5bpYdjzFPqnfDr8FuF8VVIf/KVPuUgSenr2IA8paExYro1zX4KagtkxSNsX80kQTIfNq51zTjCL9fZxurmhLIR0zwpJVZRs9i5NQe2xP6jzL-p2hV_ImdHDrX1S3X6_o5ytDHGFZ0tZweUFCUyV-ljcP/.../

https://dw.uptodown.com/dwn/9LFmqMaA-UbyOlG0oY2t5IRS0tY47ZHi8x6n5xqA2nTqOlwuSArLZLkpNN2Nhi2xXStJRtCia6qVCl71wuqqtauA6-FPeO8g5jOCpZ3GuZq6G-vPCfVhJywn8PRs-jLW/AsnTir8mb886tEXAqTwqrlDLcBoViXnOFMWzy2brkw7hQp6vYlm18YxgfYm5jGxB2zl3dJwsmxOzDG36NHu-AklDkRODbcKOTi8nzxZy5dgHbcSeSm3PJzxm612I0nIj/xJ84UG4XVnoUX1vPAawacXdt56c2EqBNDdQYE-poBraVYX3TLSEg0Nzc8ybUhsBZ-k2wCTXdluSdVTrWjo0xMu6zl-fnq1ZYXN-n3az9-Ork83d8xt-9RpYh5yJz8ixZ/.../

http://dw.uptodown.com/dwn/JFERIb79sZSH3vdLhkGJYJkSzcDtH1OdXt4yOFR2Sn7SbYzdvw4XNbKYV3VBCr5MfBn9mXmNmERQqk0sMjfikasLe_BPHw-xifi0HUr6W9Nudk_lL3featndij2Z8sb5/IypfLpwZ01C66pJK41p6va11oTNDlAurc9CxM3CKcNPD4THprvQ4QJ8kAXHpPPPaZxf23_WFn0KTYKdV5zln-s3EyPGSYbWHVN05QE6k66En0QjJYpXVGM2Rp0tVShjI/bepxrF_hgrhBbcSOTbVx14lbWd1eurJES9oovuanXkGqdeyDFuPWAaRpn95kPx3IjriA3nYKUdz5rAdAsqwbL7ahYxNS90jsktLidopM70aZmvg8hVP_UGNzxwsjz4sU/.../

http://dw.uptodown.com/dwn/8RjEnRhfLhU-pci-9HRwbl83gm3C4-kmooLum942uDjgPzJ8svOb4M8_9CV_5sW5_isIujpfO4Xdsu6dGRfILldvRV6NtDxEQUi9w0VgBEexht7iotRCG7n9uyR-J5Sw/T07z1wqux-JUGtay67tY3pygfNGdZD70FwCVzi5n5vO7-Y_cvK9rJoVqIlf3azDBlW2v4kxftKNTeL2HOPzWru7KNDCI02OU63KcpVpf53bFkhIEcIkFvkWUnpH9pYZo/VkOBEGkwsz1EJWyuWdQme7jUA0ArD6T1WlV2CHXtFDJvDfnskEoiN2wr8VEKeXgO2s25JNlHFIT2BUUTm_326xAlTIiPtf-_s8ViOXd5oxEPWjQSkDCeQylsHY4kqizf/.../

http://dw.uptodown.com/dwn/lfRo8TCmVrnDr64Y2hIAZxS4X3PcE4qkCnMlgN3aWgWtdKKuv6v3Y14VvCdv_47qiDFgGqxNAkz05oJxIhl3yTqTCp-ErF2rSuszhtHR23s4G-vQn4XqIk3f5yF_tlbd/zj0UnP1EURdVsEL8mFeozTwt0FlWugSYlqjwAY3NbkpwKYefRQ8tg7HrrduD5mQHcpsl27HTJ4uYgknDRgpXKHgLaKEsJmBJXyA5oKxdG81RoDoHY6Ws3MZ1nDLibAtW/kbYTvjXYgSfuUjqTU93Z8BmBp7hEf3fzdPKsQS59syqrE8kLkCMBOfGxjq2Z2NOVNxssTjAz8EEAdRNgzAXeEvKiU1PVKv75cL2bLwcuhoQNOYSgLpgY1EkQhHPiUR6y/.../

http://dw.uptodown.com/dwn/Gw4TO8EH1shjl8C0PGIX8ZPgCWwELJySnZXSPODsZLYs87mC-Tnm1M1HijczbMz2yg6TL7jpAf9-75Pf9N-3_N0ZsoSBjT8Y4iJ0vyziCKS1rKEDhbx5ruBEU8mXyXS7/RH02CBxl8lm8jGur2BXEUFTphgvDhLVj12POyJYx0mfK8thVSJHGK84KWIa2_mOvB5CZY1ovAeVM3bZp1X_gJLcWB5oWnfPC3Q-jBULvIQSvoy1z420Bo5SKTuNpO_d6/TBiFXoyRFl2JxbVlJD0OgYdPEsngMHkPMWE9CWWO_RoLaEssBoIaaLc5yScVAlgq_yo7YrpO4gGra4Rk9i0u8aOSLgkDj3DZ83Mxun0s1eE6K_kIaEoOko5ZWBTuJ2og/.../

http://dw.uptodown.com/dwn/amW_rqOD03Phy5aIkD7lVI4DwxIJzyVGFnKjG10Ef1x9gtGA7BbidcjJT3mSLepi3MwF7JRzvr7vMJ2SdWaXeZ2WkyV7Hmf8KOdzFVaAkzJnfkYRD3Kn1sn04KQ_oYtQ/APy5z60AnrqBGmz8Gn8_Wi3vqOykQgnknkFbCQQJ_QF8Vc8E01KkejRqDfyWGj8dKeLvbhf2vNE9B0BD2xbyIW4gUfZyLBrtXuESXUZI9prCe6uOl1Wk5Vfyb-9uWsLK/Mcg6D9UlIVcCx6_43gxSzTaLcDrqdlsTSsG9rGbYFaTsPaMFn0Uqu-mAPGpunaZnpnTM0JdJIRIrAeU5TY1BdkbkaStyY46--wmWt-N4KAU7gABzXKW6pLgxnbT3L5Ul/.../

Latest 30 of 170 download URLs

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to installer.jdownloader.org  (85.131.130.148:80)

Remove webinstaller.exe - Powered by Reason Core Security