air718a.exe

Winston Project

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application air718a.exe by Winston Project has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn77.airdwnlds.com. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Eaarnsosd & co.  (signed by Winston Project)

Description:
Oidlbxqqp

Version:
20.25.1.13

MD5:
f64c632dbeb362ff95347a36a1e179b5

SHA-1:
86124719ef11b84a394b495d1ecb0e31ef91027f

SHA-256:
1c49d7c88774370c4afad887b17207bcfcf5b945fe41782f1a698a49c6a2f81f

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 12:37:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Brightcircle.WinstonProject.Installer (M)
15.10.21.18

File size:
12.1 MB (12,719,552 bytes)

Copyright:
Copyright Qzcae

Trademarks:
Xtesxkxdx is a trademark of Tibzq

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\air718a.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/19/2014 10:00:00 PM

Valid to:
10/20/2015 9:59:59 PM

Subject:
CN=Winston Project, O=Winston Project, STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Cyprus, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B312FD1B7F10CF48C48080B24091FB8E

File PE Metadata
Compilation timestamp:
12/4/2012 11:55:11 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
393216:/j+uvGEfmSM7dKem+q8IHToyVlVK17apiH:/hGcmxKemYFmE1TH

Entry address:
0x412D

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 73, 45, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 74, 45, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 74, 45, 00, 56, A3, F4, E7, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8B, 3B, 00, 00, A3, 50, E8, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A9, B2, 40, 00, FF, 15, AC, 74, 45, 00, 83, EC, 14, C7, 44, 24, 04, AA, B2, 40, 00, C7...
 
[+]

Code size:
33.5 KB (34,304 bytes)

The file air718a.exe has been seen being distributed by the following URL.

Remove air718a.exe - Powered by Reason Core Security