zhuodashi-setup-2.4.0.2.exe

卓大师刷机专家

北京耘升天下科技有限公司

The application zhuodashi-setup-2.4.0.2.exe, “卓大师刷机专家 Setup ” by 北京耘升天下科技有限公司 has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from static.opda.com.
Publisher:
OPDA Team   (signed by 北京耘升天下科技有限公司)

Product:
卓大师刷机专家

Description:
卓大师刷机专家 Setup

Version:
2.4.0

MD5:
9e93954b1b1464748a0b18f7c2c59a9b

SHA-1:
cfa6a2185311fabc4eafd6b845c1d6b57622c62b

SHA-256:
f2beafc9c07213ded42ab2c977086901a4c2c27fa7cc728aac76bfd615409dce

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/26/2024 2:01:15 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.IM (L)
17.1.24.20

File size:
14 MB (14,729,536 bytes)

Product version:
2.4.0

Copyright:
Copyright ?OPDA Team 2011-2014

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\zhuodashi-setup-2.4.0.2.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/15/2013 1:00:00 AM

Valid to:
3/17/2014 12:59:59 AM

Subject:
CN=北京耘升天下科技有限公司, OU=Software, O=北京耘升天下科技有限公司, L=Beijing, S=Beijing, C=CN

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
31319ECFE88565C288BB66FDF72D8B13

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file zhuodashi-setup-2.4.0.2.exe has been seen being distributed by the following URL.

http://static.opda.com/.../ZhuoDaShi-setup-2.4.0.2.exe

Remove zhuodashi-setup-2.4.0.2.exe - Powered by Reason Core Security