bandoffer.exe

ProWebList

The application bandoffer.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from alwaysdelivermore.com.
Publisher:
ProWebList

Product:
ProWebList

Version:
3.1.0.1

MD5:
3d429322e4f5b26cb80fc9f0878536bf

SHA-1:
a03d5f50949158749a81a474144ca7c7defa5632

SHA-256:
b2b6c5f3d20869137584d8a1ebb77cbb9d286e27d9b15adafbe1d906cc801333

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/28/2024 2:37:24 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.A.33187
7.11.202.6

avast!
Win32:Adware-gen [Adw]
2014.9-150425

Baidu Antivirus
PUA.Win32.Agent
4.0.3.15116

Kaspersky
not-a-virus:AdWare.Win32.OutBrowse
14.0.0.2138

McAfee
Artemis!3D429322E4F5
5600.6785

Panda Antivirus
Generic Suspicious
15.04.25.08

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Trend Micro House Call
Suspicious_GEN.F47V0115
7.2.16

Trend Micro
TROJ_GEN.R0EBC0OBG15
10.465.25

Vba32 AntiVirus
AdWare.OutBrowse
3.12.26.3

File size:
306.3 KB (313,701 bytes)

Product version:
3.1.0.1

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\bandoffer.exe

File PE Metadata
Compilation timestamp:
5/11/2014 3:03:30 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:bwHysNR0nIUkVG20jmlx/yqvGVRgC3qEFy7AaaNDlPFkkpMar:wNR0nIUkxjlxVOVCiFyslDrkkpMar

Entry address:
0x30B6

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 78, 37, 42, 00, E8, 95, 2D, 00, 00, A3, C4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 80, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, C0, 2E, 42, 00, E8, 3F, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 2D, 2A...
 
[+]

Entropy:
7.9455

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file bandoffer.exe has been seen being distributed by the following URL.

Remove bandoffer.exe - Powered by Reason Core Security