0qvdfl1btsq==1.exe

Discovery App

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application 0qvdfl1btsq==1.exe by Discovery App has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn.seeresultshub.com.
Publisher:
Discovery App  (signed and verified)

Version:
2.0.5837.34972

MD5:
9ab395d6d121e3a8802a069669144690

SHA-1:
2e9fe921a6560141a6d746de2cd917be5160fa58

SHA-256:
c52e6235216cc9267baf4a57b92a6d63a8364805ba8c39b0a3001f49f4875d80

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Belongs to the Sambreel/Yontoo progam that inserts various forms of advertising in the user's web browser, installed with minimal or no user consent.

Analysis date:
12/26/2024 5:40:18 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo.Discover.Installer (M)
16.6.10.22

File size:
308.8 KB (316,240 bytes)

Product version:
2015.12.25

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\0qvdfl1btsq==1.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/25/2015 7:00:00 AM

Valid to:
3/25/2016 6:59:59 AM

Subject:
CN=Discovery App, O=Discovery App, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
510E3F5ACE52C22C76DC87DB7D1FCCE8

File PE Metadata
Compilation timestamp:
10/27/2015 3:23:46 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:i+WYNeeBVT3DoFFjuvf/toNQ8dqLuJoU0U7Hd8CntQOHHM+HFFTjXdpNnT2S:iL3eBVT3D0Fw/tN8dkmLtpHHHrh7P

Entry address:
0x3A5E

Entry point:
81, EC, CC, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, BF, D8, A1, 40, 00, 59, 89, 6C, 24, 10, 8B, DD, 8B, F1, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, A4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 24, 3E, 47, 00, E8, A4, 33, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, BD, 46, 00, 8D, 44, 24, 30, 50, 55, 68, 60, A2, 40, 00, FF, 15, 80, 91, 40, 00, 68, 64, A2, 40, 00, 68, C0, BD, 46, 00, E8, 57, 37, 00, 00, FF, 15, 9C, 90, 40, 00, 50, 68, A0, 40, 4C, 00, E8, 46, 37, 00, 00, 55, FF, 15, BC...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
30 KB (30,720 bytes)

The file 0qvdfl1btsq==1.exe has been seen being distributed by the following URL.

Remove 0qvdfl1btsq==1.exe - Powered by Reason Core Security