win32 disk imager.exe

Smart Secure Software S.l.

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application win32 disk imager.exe by Smart Secure Software S.l has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Softpulse SoftwareBundler installer. The file has been seen being downloaded from ttb.gufile.com.
Publisher:
Smart Secure Software S.l.  (signed and verified)

Version:
1.0.0.1

MD5:
70a27a614110cfd3e7fd5e6b0cc5082a

SHA-1:
62cef5ae1af83a5d3a4fa4810f508b2f26b409d7

SHA-256:
5a99e91ce83cefb64ef57f89da6ebf1a2ec626a7dd65976218eb56cc2942570c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/25/2024 3:56:41 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softpulse.SmartSec.Bundler (M)
16.7.6.9

File size:
1.3 MB (1,391,624 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Language:
English

Common path:
C:\users\{user}\downloads\win32 disk imager.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/16/2014 8:00:00 PM

Valid to:
6/17/2015 7:59:59 PM

Subject:
CN=Smart Secure Software S.l., O=Smart Secure Software S.l., L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
47353B4EEC0D902A135E20BEE1A66817

File PE Metadata
Compilation timestamp:
9/29/2014 7:36:45 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:TssvOxBnSZWbYZCfOf/6XSIgmdofIaZnRbkY+kOc:TKSZWJfOH6pDdofIa/x9

Entry address:
0x7D80

Entry point:
E8, C8, 41, 00, 00, E9, 7F, FE, FF, FF, E9, 3E, 27, 00, 00, FF, 35, 94, 9E, 47, 00, FF, 15, A4, 70, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 01, 6A, 00, E8, 0A, 49, 00, 00, 59, 59, E9, 22, 49, 00, 00, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, 62, 49, 00, 00, 59, 85, C0, 74, 11, FF, 75, 08, E8, C0, 2C, 00, 00, 59, 85, C0, 74, E6, 8B, E5, 5D, C3, 6A, 01, 8D, 45, FC, C7, 45, FC, 08, 07, 47, 00, 50, 8D, 4D, F0, E8, 27, 30, 00, 00, 68, 1C, 6C, 47, 00, 8D, 45, F0, C7, 45, F0, 00, 07, 47, 00, 50, E8, 7C, 27, 00...
 
[+]

Entropy:
7.5790

Code size:
85.5 KB (87,552 bytes)

The file win32 disk imager.exe has been seen being distributed by the following URL.

Remove win32 disk imager.exe - Powered by Reason Core Security