buzzdock-a220130215.exe

Buzzdock

Alactro LLC

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application buzzdock-a220130215.exe by Alactro has been detected as adware by 8 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from dl-2.kbm2.com.
Publisher:
Alactro LLC  (signed and verified)

Product:
Buzzdock

Description:
Installer

Version:
2013.2.13.1704

MD5:
5de51e2827d36a8e1429fe3f3f1ad115

SHA-1:
8a5055e675ba6a7b2832801e66752699ec128e9b

SHA-256:
59e4ab518c754b2f0c42dfd1a4059949d70452c20fb87058131c69fcb1bb8ba2

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Belongs to the Sambreel/Yontoo progam that inserts various forms of advertising in the user's web browser, installed with minimal or no user consent.

Analysis date:
11/14/2024 1:54:23 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Yontoo.Gen2
7.11.106.194

AVG
AdInject.Alactro
2015.0.3327

Comodo Security
UnclassifiedMalware
17077

Dr.Web
Adware.Plugin.11
9.0.1.0281

ESET NOD32
Win32/Adware.Yontoo (variant)
8.8895

Reason Heuristics
PUP.Installer.Alactro.T
14.10.8.14

Trend Micro House Call
TROJ_GEN.R0CBH0AJ113
7.2.281

VIPRE Antivirus
Yontoo
22226

File size:
1.3 MB (1,362,440 bytes)

Product version:
2.0.1.1

Copyright:
Copyright (c) 2013 Alactro LLC. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\buzzdock-a220130215.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
5/15/2012 4:01:43 PM

Valid to:
5/26/2013 5:13:23 PM

Subject:
CN=Alactro LLC, O=Alactro LLC, L=Carlsbad, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
046CAA7E02C7FB

File PE Metadata
Compilation timestamp:
3/10/2011 9:55:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:BbfU+/TrdcAeAbxYSVBVDmL2A7UJFxpIXa2kpu8m+Z/mdH/R+U7:OUBcSiS1mLWH5m+kdpx

Entry address:
0x15B4

Entry point:
55, 8B, EC, 81, EC, CC, 05, 00, 00, 53, 56, 33, DB, 57, C6, 85, 34, FA, FF, FF, 00, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 00, 40, 40, 00, FF, 15, 70, 30, 40, 00, 89, 45, F8, 8D, 85, 3C, FE, FF, FF, 50, C7, 85, 3C, FE, FF, FF, 94, 00, 00, 00, FF, 15, 6C, 30, 40, 00, 85, C0, 75, 21, FF, 15, 14, 30, 40, 00, 50, 68, A8, 32, 40, 00, E8, 36, FA, FF, FF, 59, C7, 05, 04, 40, 40, 00, FF, 00, 00, 00, E9, 20, 02, 00, 00, 8B, 35, 68, 30, 40, 00, 68, 94, 32, 40, 00, 68, 84, 32, 40, 00, FF, D6, 50, FF, 15, 64, 30, 40...
 
[+]

Entropy:
7.9973

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file buzzdock-a220130215.exe has been seen being distributed by the following URL.

Remove buzzdock-a220130215.exe - Powered by Reason Core Security