125aa195_stp.exe

The application 125aa195_stp.exe has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from winipoly.me.
MD5:
18fe6f6b0aa05e6b652db70d6f7f46a0

SHA-1:
af5510a4f70b7e47a76dbdd1898f0673f8952216

SHA-256:
f94e44e9b5b9718f17d6f72968e5098a9a4583a159c9efaa933882accb21542b

Scanner detections:
6 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/5/2024 2:25:34 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2016.01.06

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
14.0.0.860

McAfee
Trojan.Artemis!18FE6F6B0AA0
18.0.204.0

nProtect
Trojan-Dropper/W32.Agent.50166
16.01.05.01

Qihoo 360 Security
QVM42.0.Malware.Gen
1.0.0.1077

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
49 KB (50,166 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\125aa195_stp.exe

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:81cVhpQI2EQK0iPDh84nScF15GYbWjXO3XJt5uWqFAUKoq6Vb3Y5h4AgVtKzTN24:aQpQ5EP0ijnRTXJt5uWF0b3Y5T2KzhT

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file 125aa195_stp.exe has been seen being distributed by the following URL.

Remove 125aa195_stp.exe - Powered by Reason Core Security