2ffe7625_stp.exe

Hotspot Shield

AnchorFree Inc

This is the downloadable installer to AnchorFree's Hotsopt Shield, an ad-supported VPN client that integrates with the browser. The free version injects ads in the web browser. The application 2ffe7625_stp.exe by AnchorFree Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the HotspotShield installer. The file has been seen being downloaded from indir.gezginler.net and multiple other hosts.
Publisher:
AnchorFree Inc  (signed and verified)

Product:
Hotspot Shield

Version:
5.2.1.9543

MD5:
a171dcf4c4042a0dc7653e1b48521ea7

SHA-1:
bbbc825721a20a900172e680f43b9cc3ecc022e0

SHA-256:
37118edbc970a8dabddbd161bbbe6ed4667375b066e1bcfd86cdfac6debd6b86

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 3:16:25 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.AnchorFree.Installer.Meta (L)
16.6.10.9

File size:
12.8 MB (13,427,552 bytes)

Product version:
5.2.1.9543

File type:
Executable application (Win32 EXE)

Installer:
HotspotShield

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\2ffe7625_stp.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/21/2015 5:30:00 AM

Valid to:
6/14/2016 5:29:59 AM

Subject:
CN=AnchorFree Inc, O=AnchorFree Inc, L=Menlo Park, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3DAA06F4E8BE7B2AE8FC57BA8578B7D9

File PE Metadata
Compilation timestamp:
12/27/2015 11:55:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:Dvfy7/yMU9bNU/dEJySHnlJ15xvwJ7I1FwkJN:+7KMUN0qHnruJ+pj

Entry address:
0x327D

Entry point:
81, EC, D4, 02, 00, 00, 55, 56, 6A, 20, 33, ED, 5E, 89, 6C, 24, 0C, 68, 01, 80, 00, 00, C7, 44, 24, 0C, 00, A3, 40, 00, 89, 6C, 24, 18, FF, 15, B0, 80, 40, 00, FF, 15, AC, 80, 40, 00, 66, 3D, 06, 00, 74, 11, 55, E8, 51, 31, 00, 00, 3B, C5, 74, 07, 68, 00, 0C, 00, 00, FF, D0, 53, 57, 68, F4, A2, 40, 00, E8, CE, 30, 00, 00, 68, EC, A2, 40, 00, E8, C4, 30, 00, 00, 68, E0, A2, 40, 00, E8, BA, 30, 00, 00, 6A, 09, E8, 1F, 31, 00, 00, 6A, 07, E8, 18, 31, 00, 00, A3, 44, 8A, 7A, 00, FF, 15, 44, 80, 40, 00, 55, FF...
 
[+]

Entropy:
7.9961  (probably packed)

Code size:
24.5 KB (25,088 bytes)

The file 2ffe7625_stp.exe has been seen being distributed by the following 50 URLs.

http://indir.gezginler.net/i/15284/.../

http://www.downloadpresentcity.com/vmAcNFHG2x6_ipzCfWnESRxg8RbHmlWu9fZnZQVaBaH BM3vd4G1krOHISIwzMroFbmVIL1F2GOVDkvYHcKlyvvrQm0cB5xSlevYD8E6sufTGw_dcUXCpM92MIb8_TPjLz1rNnSgINf7Tx13yAK8CdKL3G7mMpOztiMxww90 BAY2Z_PySk=-GxEDAGQ t_Hj4A8ixyPqoA8RFl4pGYIwkQP2thhiPom9Nw48WWPkZxGYW36MZf8 s6Pf8Z7qFB5NYiT5d8lvO0OkPIuuj6mJ0iMoxUe5JAMSUvs8pf68hv15GPKUpgr_THFKfUucjWYntRTclL5ipCzHi0hopxCvzVhPOB8tspzHHEIxyFu4ThLQzm6jEJcpnmFhFf1kcc1m6t4b7tZavxmCee1J8vt8SmjFqI8cTJQUb dZ4XHNiJN4PZ _jeOxzwwAcH ZBje1YhADN A26ounXCnW d86G1gjif1HOBsUNkKYg5cjUeKsvQ_g6blKXrRu147PLzTXThFWElcWh Q2JNgP7BcvuKYRVNGs1d2jddeln es1J_Xw2OY1A_CIkw7A3FJOupkgatRZ8VN7x7giiJq7kbRQfTt0WvoJZ_aQ_XWJRgqgxsIA05K9Zv1UlYpmuXI5C0DM0vWgYLP2mUJ9lByeU_yC2gqp7rHYMq9ToPDwnskoebmilT0bdyYbOCd7lv3CV fx4LsWw6o3JfkPJflXUQrnlq7Br MpZ11vIsiFVbx5Sqad3N9 eg8eNiexJLco67kboGTV1pRdTe3ZSatgJykz1auHjq91dn8hkvjZ5v0Pa93v6CYZApgjzkykhGRanQVCD ULayhVjqgs6cRqyU9sMKxo2lYYE3bY5tMO3LqJ0FE21GQqtjQrsfDaKLDtSv2 fmr4gAA1f uhtFs d q7hwxDCUISbhBVDXpb2I2sYKFLL7F2J0oi_KbRThDbtO Ck1

http://indir.gezginler.net/i/15284/.../

http://indir.gezginler.net/i/15284/.../

http://www.applicationconecptclean.com/e1MDt4p_WJZ3P0WSMiEMszUWFeFAMWO3yCgLbnYqeFnET PsAnt8fJqKVYcLiFOajZrv2ZSKQRrs3S fDtf9SwM69NB5_9FW6qPuLL0AYBY9ECNvMyozInSyhpl4NEmJbuYRffGrOid8ObfufAWw5oMafuMxXEJwIwqehXyUKgcFYeaFpY8DNCgbDFv3dj6TXoo6ZxryKuomkMR3bj76_vJ81gEg nIWIihcttf9r5JuXbLqu5loTSEbJHIIYTRjOF1FI 7fLJjTGEVF3ICDi3 4anoQtM4eDFskQk3fRc_cWHI3afjtVtVUjL3SsudvK30kmU433sARXSJgpSch2Hg0DccsK0QGbttz7WwqPDr57GozrloauKOWS5 zOWHUQKQC8i0JP_1M V79K8OYtV0rDwlP2_a7zqZ_tKRxiFqMZf1idRgJvtGT64YSyl3ZxZGFhK56YDa9_sheoxbSyhXFs1tbVAAwv1qXNlELLuS2WzxTRFqWHRmSpWVY8stSn9ss0kiyIioQzN4oehcpsL6t7iR9Wg5_DXrqGS9Riz0sudlCSmvxgm4eIFEQq_dZGiNeP4m Qtd0IpBsuraVwclba9vZGM cKLgApU3Su1XSo6JE8KpUdT0nwWKTn40dRmlmAoKf-G1AAAGRwXkyTWpQPwgYcOCUUEK0D1cAGrqjx2hN0cTU7twK05ZIqFyJcc0q4EBzFhTTiBC6UAURjg5kEZbuvnQeuUuMIMP4R-e

http://s01.mydiv-downloads.net/download/aHR0cDovL3NvZnQubXlkaXYubmV0L3dpbi9kb3dubG9hZC1Ib3RzcG90LVNoaWVsZC5odG1s/47bfe/56f2a6c4335af/soft/dfiles/ru/win/Hotspot-Shield/.../HSS-773.exe

http://www.downloadpresentcity.com/MdZsMSY6zZC0RJcDQrO3mHVIpvnpHCpohq9Ru8AgGqvLtb4LNuwtswpZGOKRkpoUqIQ3qqRE cBT53aLfaIda20nfVtdSwa42knmVJkpUnXUymSmXR7LPl94l4MyuMtkLl7zy2qmK_GbA1IoiasqNQGQP6hV176ChSwSje0Onqh5NT5pWXI=-GxUDAGRIryqLPAKWuEyMhr4JFjCRA_a2GGI ib03DjxZY RnEZhndW_N0j7lvVx4b7XIGGMoF0H0GZBVDCgrzOrENj_x9OrPzlVeARmN1k5h2WLCjkG8d3ZHafcQsGUxufZaqJWpYzVVrmgZs2BVLHNAbrHDMnexS6kPmgVSdxwHE0rkjliDCkwm5DrS21Wi 3Q7zjVHhoP7Ni5V7594XPHXt4tthiWNAalWfarsb7NKJnuShyYxu5Ph3T6FwekTU_AONnT TN U90REdyJOk5alz7mTpSnn96l4uAPc07HQV59VeF MG4W3fqHZZLhABlTEKtwjtZxSai0f1FH__n5Q_bjGvJkvjgUCx5puXSPx8cgWtDO4YFCiUrSbAOGxak_JmtQhwuwTDk5oxnkI0H hopHX5bD08TYFL6Zk5JIHR fnhEveqUOaKglyE0AnUk_pRkdUhBufByvPDbW78wewhSPXUXDpRMV5sta2k6 9KHIY6Ii1bKwkHgsMITgZvgNj8ruXsz0MywBl6 Moooim8A7Nknnddz9TJZu_suSNLRi8fnC9tcHFnvTY1Kaor6OlkHD WsvAeQQH1Ary5Pl445wBXxiBq9dq89kdkk17t0yoXIM_XvtBjSiknju5TH07yAgnT7f5TL3mSxWcHtQWvl_GQoAh8WhjpuRwkvKG07k6dnTwYw0GQQdZsuDJm KooIJTyfyVMZ7nbc9qMMrOXKZpPuTHkHeL4XucNPljT4VdKXvZ2gQwNTX9uauvfHJxL1r 7 h_ZKVe

http://www.tamindir.com/indir/MjAxNi0wMi0yMSAyMzo0NDowMQ==/hotspot-shield/windows/.../

http://totalsoft.org/go.php?site=http://mydati.com//download/.../HSS-773.exe

temp:hotspot-shield-5.2.1 [1].exe

http://www.downloadpresentcity.com/UoXbEyg9cGHlaFGK2gL8h2bLluflc4w0 ifkwVQiGgHekUgtPdyQ lWBXAOnfQH0PJP6sQ7sXSyexxXVE81bY5cZN5BRxZFN4O6u62ClT6xKmhBAq2vN4bzVvU jrDUAumIVfL2hwTXGiORpGSdd44FY8lVNpCRUz3bvFSlypwoJLzdNWlo=-GxUDAGRITxoH_AfqeLmYXQIXkWAiB xtMcR8EntvHHiyxsjPIjCXfOvLT7Vn22fFe6sOYyNHb3WaXSJbRGtZLMuBprEjETBC5jzSp2EMemAjQNA_C1ixcNFxcG_m52kyxhMWIUaem1GsSaZhfu5f gobKK37iPR0jk8n2_80fKehPoE9nVkx3kkPijMe PluRvvbuHErkRzyDdTy6BSBCLdQuQ425H4c8QMnpL2SnAbzMyk1gxw8S8uhyArZHOSxHVfEfHgydLYLAtqV8kpvyQc2PxgayhTJFUr9xfUGFYJWD9DEUk5ea1fn8xOQoOvtiucTjnGowQzdEaf3 7XZ0fzTmgj hEtVrjTkH11lwCQrEiY6WnH4TArxeeZAUZhL623JHBWWV4fAZ6pyMV4Q92YAxJ4AreTgjcIjZFGZNqmFDwQxm0LU KdM1JX58_UrHoslyd62aYHy0DbXQX5CquTnLWRCHnsbPY 6Hz1zCyDWsk_7N0ZC5lNboF_8OTBt7R7VddBVpNi_eecCWdX9FTdwtIpaCssTFdgtoTdkz3hXL8FKMBFVXil2pttHXbj6T EyS_foYru2u7cKHIZY5_OKgNG_kymDvaK kKAtIoszD nrJ2XPE e bJvi1SNh65xI7P_XXp0ts5TBo pz2WZ8761CZKsxkUqc1DzkJWwy R3T22Zf7cd ZgPQCfxdO6FROvt5nR7n8iCgAwHaNEaROG9FRexKWJg0GDBiN0MA4xO0hZIxo9K7zKgrq2_BaXR9hAw50621VJ

http://www.clearfileclear.com/WVl6OTRQVzVRZFd0bWJXTkxiek5uVERJMFVXOUNNazloY25sTVkyUmtObUprV0ZCdFltSTRRV0owT0hwTmRGRWxNMFFtWXoxcWVrZ3hUelV6Wmt4d2RHeGtSRkJoUVdjelRXbFZOM2hMYTJGWlVUTnhSMlZWZDNkV04weHhkRmRhTWtkUlkwVlNSaVV5UmpGRWFsUnViVU14VGtNNWRXeGpNMWRKWjNaUVpHZEpSbk5YWWtNMGVtSkhXbmRsU0dWT1ZFa3pRVXQ0ZUhwemJsRTRTWFp5WkdsUWVtRmFhRkpQWmxWa1FrcFRUV0paUm1kWVdEWm1kamQ1VkZveU1UbHFSRTUwYlV0a01tNURUVkZQWm10UlIzbFlUREpQY1ZoWVVVY3pNbFZWWjNkYWR5VXpSQ1prYjNkdWJHOWhaRUZ6UFdodmRITndiM1F0YzJocFpXeGtMVFV1TWk0eExtVjRaU1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6UVNVeVJpVXlSbkJtTG1KbGJtcGhiV2x1YzNSeVlXaHpMbU52YlNVeVJuTWxNa1l4TkRVM01EYzNOVGt6SlRKR1pXNGxNa1k0SlRKR05DVXlSamcwTlRjNUxURTRNRGt3TXpZdGFHOTBjM0J2ZEMxemFHbGxiR1F1WlhobA==

http://www.applicationsbundlevault.com/S3hs5b0oLIuLpH fg6yj0lQc3P9bgpNrjIGlG7YeZ9Sw1uagyM yb1bqxehJX1RK7OWtycGJSGvKsxbzqrlTepzdBlnXoCr_8LAKUo1AY1ngwDSUYge8DV5JPrvt__tJcJP3IDvKBIWOkRW4UGBCSnPAjgBYNd W8yqkZx5RYqhptFyL lrvTrlQ2gvljtBxp6kfNTSzj2mKB0u4ITsnvyLDP37RReaw8n2ocIkvBJKZwG ggcCAeYKXWin01Yr399OZ_KA qnOXBUn183WEUsEX07OqVQ2enNz UtxDikPdoJJKakRCWNUggFkwVqcew29o F_FTNIRxUV83ypPZvph9Smwpwud5t_wcS91k0YrbPL9inHpgVcEUs YrUcXAuk0zgIziRDI_rREwpiCytLL6pQ7EHdB5VjcdyHKVgXMWm59RDm9paTuj7hWyQ_TvBiOta5riTjlPrJoN4f5AevLyLv5Wxx2QguvFhT1KFzFokX8wtxFbBlfvZt1bbtfFDmqhxJv0HBpcCmEyd6Kgk34RH47OpAoAVr5 Bzk NftxhT8mihmmc5pmX8WNfRNRmQQfcccPdUKIvqgOKDdgY9Z1XVISXz5cSI7jqZWKBj6bkoVC3o=-Gy8AAETnFhN8g0CodkJyk02CFtzULsSRWSSS2AZy46w_ skSgT7MKrq5Bc2dzJTjBQ==-e

http://www.applicationsbundlevault.com/DbTIselG4ve aKeLykj4I8MTFSuZi02qzbmjpahGRol5yZDswrfBSgL9zt0ZXMTZwq0jnCTUtaxWcqTHqM0GtONs urMtJdnqA_OCEBxkOnLdtyqb3R2RHDUPNz2Bq8GjrLRHBzHPhAKv7tB2k6iwVAwX1moznsO7th0xMQ2Wdp5jjcdDiggQRBAT2K1TfSokbMB8t8DHniO8X2FucS1iSZkQtTlWESJeN7sk sSMRARdOWCw ArECXWDyFjtizmLGCQoE1UbAmI9ZudAdNEqdoODY6ezfj60pywX2MPR3dRMyDqMdioU3oY9pPa55cZvHjfkXkru1WY8y9rC3 T28XhruUmWW Kgn57ueKm3BoMtP8G9XhF_EHdp07BHnNURMjVzMxkTDVaEOxqr4D3HA7SkVEXV6dduR9wb9dPJn7JDU3RLqm8JldVdIDkjQSmrAmEw_26y9uLDVBBH9lsATcvAN0EdHge3EBz0SPTykzGvV7depMPwL5Mmc1bywhKUYRTMkUdcuwAR5EmttdAt ER4NZXbYAUiWpP9i1S_PTcWogjQYvFHz933OKcaNvAuSjY2FYh_JXZBLMDHPCzpXbC7kUXqeF1Jnl630or_jyht999Xr8=-Gy8AAETnFhN8g0CodkJyk02CFtzULsSRWSSS2AZy46w_ skSgT7MKrq5Bc2dzJTjBQ==-e

http://s1.download.net.pl/0b3c0fc1fbhss-521-instaell-plaein-773-plaein.exe

http://www.ranchmetabits.com/uiMCK7iUQF7q0rv0rY4PNVdKsaNe0Pbmknr3Y9i5v6LsiP4zKk0qBH 0OtuqK5M51it43NuSoQO9EoFofqfzS3YFe5j8LT833r5MGfR7i61I2YwMGlgdxCWW2KvWnhCZkg6gVEv1jlyGdwLKztg0xhApxxBZzrJ_pNvRS228tTrMwU Ft10=-GxEDAGR6PflxyEfA8QVq5CUHqIWJHLC3xRDzSey9ceDJGiM_i8A88msux rOrvHEe6rjc2Qv_nztOLasZx8T9XUDL55pP2R5CmKPV 8vJdrjRwzJmpiFU1Scbwr6iFG5kye6HLhttqETHavpe4n1iQu7xRodVy_TBezuiVZPCCQFig8YgnaAtv3CnESnMM77om7S3S1ErgAfdbzoXAS2gd1AJtH4PRXooYCBwZHKE6ysq8y_yxZfo48gTObHHEhCvKyUkuOtdz4PHi5wzRf3C2qjj6QIZR3_mHhlcLJTjEPscWK8FuQZ_vmQkSoeb4uRXJsGvmQ_Tn8egxPSuMHYTwMx0Nq6U8R620_zfKQaVl2SeyMcgytMj9RAbqp81KjCrfVjhSTK2uOU5DI2qZfMuYOZ7sNRJegb48M A5F7I6XYcIvDKH1LGKDugZ4XKklKpMl2 z0HMl4Y8hrWAXo04skeHQSoMenENpeX32ULHWYMNLddw6AvBbXKvH LJj2T c6912YpUc0nEKD6cHX93EypU N6hdiQvfD2w7XvAt2sRwWhu7vsIOzyLaKQWgUaUK_y21 6th5nZRX vDAsbjjcAuSXpL7nWSjYb7BfoHC1tyz2eWbpvpUlXHhtkac_3kxGM0Lln0F6CndJmYbSzveLBkNm1rcU67SKrpni3T0Sifm5pGPpMVSVSY YYtYHxgLiCUdKyvW_EgIAkJwnGr5euNrW08SFyfm 8IF5pADSvvUv2hpw4fnU XxgIlE28asWn3gYk8YTW8_rWI70ge

Latest 30 of 71 download URLs

Remove 2ffe7625_stp.exe - Powered by Reason Core Security