additionaloffers-setup.exe

TEA TIME BISCUITS

The application additionaloffers-setup.exe by TEA TIME BISCUITS has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the Tomorrow Software Installer installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from files4.downloadmaster1.com and multiple other hosts. While running, it connects to the Internet address 8a.3f.1632.ip4.static.sl-reverse.com on port 80 using the HTTP protocol.
Publisher:
Reputable Nimble Installer Setup  (signed by TEA TIME BISCUITS)

Product:
Reputable Nimble Installer Setup

Version:
96.7.3.3497

MD5:
a66f558fe99d148970d831fc7d11efd3

SHA-1:
1cba5c298527ba8cd7fd08b4d93de6625023192d

Scanner detections:
11 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/26/2024 5:28:25 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.3003

Baidu Antivirus
PUA.Win32.DownloadAdmin
4.0.3.15828

Dr.Web
Adware.DownloadAdmin.12
9.0.1.0240

ESET NOD32
Win32/DownloadAdmin.N potentially unwanted (variant)
9.12167

Fortinet FortiGate
W32/DownloadAdmin.K
8/28/2015

F-Secure
Application.Agent.KW
11.2015-05-09_7

IKARUS anti.virus
PUA.DownloadAdmin
t3scan.1.9.5.0

Kaspersky
not-a-virus:Downloader.Win32.DownloAdmin
14.0.0.1475

Reason Heuristics
PUP.TomorrowSoftware.TEATIMEBISCUITS.Bundler (M)
15.8.28.19

Sophos
Mal/Krap-K
4.98

VIPRE Antivirus
Trojan.Win32.Generic
43400

File size:
759.5 KB (777,704 bytes)

Product version:
96.7.3.3497

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tomorrow Software Installer

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\additionaloffers-setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/10/2015 2:00:00 AM

Valid to:
6/10/2016 1:59:59 AM

Subject:
CN=TEA TIME BISCUITS, O=TEA TIME BISCUITS, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
045E02431B8F3D0264586744F7C513CB

File PE Metadata
Compilation timestamp:
9/21/2014 5:52:07 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:u/19Veo1tjwJ+9Mjp6SVMHptL/OgvuWtuPwn9ZVYX8+H8SbnJs/CHj52ElnN3AYw:MjYo7jwJ+oMJB/Og8Pw9zYX8+pjG/2IJ

Entry address:
0x1A3490

Entry point:
60, BE, 00, 90, 4E, 00, 8D, BE, 00, 80, F1, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
748 KB (765,952 bytes)

The file additionaloffers-setup.exe has been seen being distributed by the following 20 URLs.

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=BG&cb=1208773773&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=MA&cb=584393802&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=LK&cb=1421955516&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

http://files4.downloadmaster1.com/download/.../dl?bc=1188307&pid=kmp&brand=kmplayer.com&s=noprimary&country=LK&cb=-1454017136&osName=unknown&browserName=unknown&zTmp=1&executable=1188295

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 8a.3f.1632.ip4.static.sl-reverse.com  (50.22.63.138:80)

Remove additionaloffers-setup.exe - Powered by Reason Core Security