boost_800001_1010.exe

Boost Shopping

The application boost_800001_1010.exe by Boost Shopping has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.apptilio.com.
Publisher:
Boost Shopping  (signed and verified)

MD5:
67577c3f8e2ee32ca27e159018caadf5

SHA-1:
4fd4688886f4e3778c8a4f80e1bbb955e81a5898

SHA-256:
6c27514b199a44a8843a4ce0ebb9daaf6f608f6f9ae3a7e37831d8a2b0a7024e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 11:21:23 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Betwikx (M)
16.12.22.11

File size:
882.2 KB (903,336 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\boost_800001_1010.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/24/2014 7:00:00 PM

Valid to:
7/25/2015 6:59:59 PM

Subject:
CN=Boost Shopping, O=Boost Shopping, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
177A8BFAF4DD605A74873C1AA8D4EE7E

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.6559

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file boost_800001_1010.exe has been seen being distributed by the following URL.

http://www.apptilio.com/offers/.../Boost_800001_1010.exe

Remove boost_800001_1010.exe - Powered by Reason Core Security