300614_y2.exe

Installer

Jambo Digital Ltd

The application 300614_y2.exe by Jambo Digital has been detected as adware by 22 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.wikizu.net and multiple other hosts. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
pennybee  (signed by Jambo Digital Ltd)

Product:
Installer

Description:
Main Installer

Version:
3.0.0.0

MD5:
c523ac284cbdf9cb2c4be16e4364feb2

SHA-1:
80fe868ea6f228bfd78c9bea1b543760b4a63b6f

SHA-256:
a672f073019dded748c587528141a1a0ad0c2a1d4d883eee3800d2c215a8bdb2

Scanner detections:
22 / 68

Status:
Adware

Analysis date:
11/4/2024 5:07:30 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1869073
750

Agnitum Outpost
PUA.PennyBee
7.1.1

AhnLab V3 Security
PUP/Win32.Pennybee
2014.11.04

Avira AntiVirus
Adware/PennyBee.A.23
7.11.182.246

AVG
Generic5
2016.0.3228

Bitdefender
Trojan.GenericKD.1869073
1.0.20.80

Dr.Web
Trojan.Lyrics.150
9.0.1.016

Emsisoft Anti-Malware
Trojan.GenericKD.1869073
8.15.01.16.01

ESET NOD32
Win32/AdWare.PennyBee (variant)
9.10665

F-Secure
Trojan.GenericKD.1869073
11.2015-16-01_6

G Data
Trojan.GenericKD.1869073
15.1.24

K7 AntiVirus
Adware
13.185.13888

McAfee
Artemis!C523AC284CBD
5600.6884

Microsoft Security Essentials
Adware:Win32/PennyBee
1.11104

MicroWorld eScan
Trojan.GenericKD.1869073
16.0.0.48

NANO AntiVirus
Trojan.Win32.Lyrics.ddtbvt
0.28.6.62995

nProtect
Trojan.GenericKD.1869073
14.11.03.01

Qihoo 360 Security
Win32/Virus.Adware.eb2
1.0.0.1015

Reason Heuristics
PUP.Installer.Jambo
15.1.16.1

Sophos
Generic PUA IA
4.98

Trend Micro House Call
Suspicious_GEN.F47V0722
7.2.16

VIPRE Antivirus
Trojan.Win32.Generic
34486

File size:
874.1 KB (895,064 bytes)

Product version:
3.0.0.0

Copyright:
Copyright pennybee

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\300614_y2.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/27/2014 9:00:00 PM

Valid to:
5/27/2017 8:59:59 PM

Subject:
CN=Jambo Digital Ltd, OU=Jambo Digital Ltd, O=Jambo Digital Ltd, STREET=2 Kaufman Yehezkel, STREET=tel aviv, L=tel aviv, S=TEL AVIV-JAFFA, PostalCode=6801294, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C458EED8E9EAA77E97499968CD5DD6B9

File PE Metadata
Compilation timestamp:
6/6/2009 6:41:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:MovqeDIC49lotOGHLuMSIteVWhz9EqCDxKGKfGKuI3X4eWcr6TkuQy6:Moie8KO6ulEe0eAGUGKV3Ie7wkuQb

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file 300614_y2.exe has been seen being distributed by the following 2 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove 300614_y2.exe - Powered by Reason Core Security