310714_y2.exe

MY POP SHOP LTD

The application 310714_y2.exe by MY POP SHOP has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.hakoonportal.net.
Publisher:
PennyBee  (signed by MY POP SHOP LTD)

Product:
PennyBee

Version:
1.0.1.1

MD5:
157990057455220096968a6cf991a87e

SHA-1:
3bc1e9bf9515f9992990815d1253fc326dc53729

SHA-256:
4a004fa193260f60a553bbf5a1f2d8d006b3a0061ce114bb58bb1d0dfa13e9ef

Scanner detections:
20 / 68

Status:
Adware

Analysis date:
12/4/2024 8:09:59 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Smartbar.O
750

Avira AntiVirus
APPL/Linkury.Gen2
7.11.164.206

AVG
Mypopshop
2015.0.3395

Bitdefender
Adware.Smartbar.O
1.0.20.80

Comodo Security
ApplicUnwnt
19262

Emsisoft Anti-Malware
Adware.Smartbar.O
8.15.01.16.01

ESET NOD32
MSIL/Toolbar.Linkury (variant)
8.10183

F-Secure
Adware.Smartbar.O
11.2015-16-01_6

G Data
Win32.Application.Linkury
14.8.24

IKARUS anti.virus
AdWare.Linkury
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.PennyBee.A
v2015.01.16.01

McAfee
Artemis!157990057455
5600.6884

MicroWorld eScan
Adware.Smartbar.O
16.0.0.48

NANO AntiVirus
Riskware.Win32.Linkury.dcvwxz
0.28.2.61148

nProtect
Adware.Smartbar.O
14.08.21.01

Reason Heuristics
PUP.Resoft.MYPOPSHOP
15.1.16.1

Sophos
Generic PUA MP
4.98

Trend Micro House Call
Suspicious_GEN.F47V0731
7.2.16

Trend Micro
ADW_LINKURY
10.465.16

VIPRE Antivirus
Trojan.Win32.Generic
32410

File size:
967.5 KB (990,680 bytes)

Copyright:
Author © 2014

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\310714_y2.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/6/2014 9:00:00 PM

Valid to:
7/7/2015 8:59:59 PM

Subject:
CN=MY POP SHOP LTD, O=MY POP SHOP LTD, STREET=14 Shenkar Arie, L=HERZLIYA, S=NA, PostalCode=46725, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4A7D93FD75281A37A4ADCDCD636D3ADB

File PE Metadata
Compilation timestamp:
12/25/2013 3:01:38 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:gUv5IBZ8jP92u4hlX1Wfc8S5L3j1PgsodS35tot:jhfF+DXqcf5DZ/ocpS

Entry address:
0x3358

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 14, C7, 44, 24, 10, 30, 92, 40, 00, 89, 6C, 24, 1C, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, BC, 70, 40, 00, 55, FF, 15, AC, 72, 40, 00, 6A, 08, A3, 98, 92, 42, 00, E8, B7, 2E, 00, 00, A3, E4, 91, 42, 00, 55, 8D, 44, 24, 34, 68, B4, 02, 00, 00, 50, 55, 68, 90, 06, 42, 00, FF, 15, 7C, 71, 40, 00, 68, 7C, 93, 40, 00, 68, E0, 81, 42, 00, E8, 22, 2B, 00, 00, FF, 15, 34, 71, 40, 00, BB, 00, 40, 43, 00, 50, 53, E8, 10, 2B, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file 310714_y2.exe has been seen being distributed by the following URL.

Remove 310714_y2.exe - Powered by Reason Core Security