1_offer_4.exe

Baggio Technologies (BrightCircle Investments Limited)

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application 1_offer_4.exe by Baggio Technologies (BrightCircle Investments Limited) has been detected as adware by 5 anti-malware scanners. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from 113.171.224.211 and multiple other hosts. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
MD5:
c560cd8c70fb1d087457f80b507f41e9

SHA-1:
aad6e0a16cff842a64339c9af43a005d7aef0579

SHA-256:
d7230fa00981c29c87c33404696da8d6312ec537ff5eb75782dffa4c4c938555

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
11/26/2024 10:48:23 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Win32/DH
2015.0.3272

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
14.0.0.2853

McAfee
Artemis!C560CD8C70FB
5600.6928

Reason Heuristics
Adware.BrightCircle
15.3.1.12

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

File size:
124 KB (126,952 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\1_offer_4.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/17/2014 5:30:00 AM

Valid to:
11/18/2015 5:29:59 AM

Subject:
CN=Baggio Technologies (BrightCircle Investments Limited), O=Baggio Technologies (BrightCircle Investments Limited), STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
469910CAA5B253B7B000122E7059F344

File PE Metadata
Compilation timestamp:
12/2/2014 4:28:46 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:zKCs3ZRpxisOM6g64TSfGjZewwvsuPIg93/LU72g+bTqc6oqa6NLsWjcdB7W6MBB:WxisuMTOiUPHPQig+HB6N0BCVpryja

Entry address:
0x6E54

Entry point:
E8, 92, 69, 00, 00, E9, 7F, FE, FF, FF, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, D0, 01, 32, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 2C, FA, 31, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, D0, 01, 32, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03, 00...
 
[+]

Entropy:
6.3458

Code size:
81.5 KB (83,456 bytes)

The file 1_offer_4.exe has been seen being distributed by the following 5 URLs.

http://113.171.224.211/.../1504s.exe

http://113.171.224.243/.../1504s.exe

Remove 1_offer_4.exe - Powered by Reason Core Security