compete.exe

Compete Inc

The application compete.exe by Compete Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from fastdl1.us and multiple other hosts.
Publisher:
Compete Inc  (signed and verified)

Version:
3.2.4.4311

MD5:
a29dce163229a825ddb0ebdb3cded740

SHA-1:
e35139e1bdccff8a5b3369382112eaec47043f09

SHA-256:
4a07ceb392641fd3eca8b91e8de4d6f9f97df21dc4a23b650c7ea1bb1023de3e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/6/2024 2:12:58 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Compete.Installer (M)
16.6.22.16

File size:
1.8 MB (1,923,096 bytes)

Product version:
3.2.4.4311

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\compete.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
12/21/2014 4:00:00 PM

Valid to:
3/22/2018 4:59:59 PM

Subject:
CN=Compete Inc, O=Compete Inc, L=Boston, S=Massachusetts, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0A6DDD60D9E6C4FAA56565923F8669C2

File PE Metadata
Compilation timestamp:
9/26/2011 6:21:38 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:XFlQkDwIXJYgLPqiIwwquBxhkjwuQ6jTDwkXJ2CLKcjIwwAY9LSrK:XPHDwIXJpLPAFq4hkjB3DwkXJ9LK3FAU

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 84, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 18, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Entropy:
7.9848

Packer / compiler:
Nullsoft install system v2.x

Code size:
29 KB (29,696 bytes)

The file compete.exe has been seen being distributed by the following 2 URLs.

Remove compete.exe - Powered by Reason Core Security