1_offer_2.exe

Krance Development

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application 1_offer_2.exe by Krance Development has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from savepass.downserver4.com. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Krance Development  (signed and verified)

Description:
Itecfbkddbyg

Version:
2.18.5.20

MD5:
bef470bf83eeff420a8156d1ad3157fe

SHA-1:
423f76477d807732bbf32056232ba2f6cd4487dd

SHA-256:
9423809592140ab55731afe4a56d459a51f674f4431efbd59d55d593d81f54b5

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 10:15:37 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Brightcircle.KranceDevelopment.Installer (M)
15.6.18.12

File size:
11.1 MB (11,663,736 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
Nezavisno od jezika

Common path:
C:\users\{user}\appdata\local\temp\1_offer_2.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/28/2014 2:00:00 AM

Valid to:
8/29/2015 1:59:59 AM

Subject:
CN=Krance Development, O=Krance Development, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2F8A4746EB05936853BC17805C72D300

File PE Metadata
Compilation timestamp:
12/4/2012 2:54:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
196608:C/cKojsOSuWp0hrPBtDPXICPb6RqUiqgEY25mZvRVW59wc4YYS1nfQF3Bg+AyCmO:fXhrPfPXgExqgJ2kNQ4hSNY3W+3O

Entry address:
0x4101

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, B3, 7C, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, B4, 7C, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, B4, 7C, 00, 56, A3, 6C, 23, 7C, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8B, 3B, 00, 00, A3, C8, 23, 7C, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A9, B2, 40, 00, FF, 15, AC, B4, 7C, 00, 83, EC, 14, C7, 44, 24, 04, AA, B2, 40, 00, C7...
 
[+]

Entropy:
7.9994  (probably packed)

Code size:
32.5 KB (33,280 bytes)

The file 1_offer_2.exe has been seen being distributed by the following URL.

Remove 1_offer_2.exe - Powered by Reason Core Security