counterstrike.exe

Inffinity Internet, S.L.

The application counterstrike.exe by Inffinity Internet, S.L has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from data.phpnuke.org.
Publisher:
Inffinity Internet, S.L.  (signed and verified)

MD5:
5dfdb7cf3958aa7028c491a49bc1318d

SHA-1:
406c3d0352f04cbe37d5fa57c71e4d1dbb4ca690

SHA-256:
d03ca40671486c2319b22f0cdb5c8307414363eae484be7dda8c5fc7bca8d81f

Scanner detections:
7 / 68

Status:
Adware

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
11/25/2024 11:28:43 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen
7.11.164.106

avast!
Installer-Z [PUP]
140617-1

AVG
Toolbar.Babylon
2015.0.3398

Dr.Web
Adware.Downware.1036
9.0.1.05190

ESET NOD32
Win32/Toggle
8.10172

Reason Heuristics
PUP.InffinityInternetSL.N
14.8.7.2

VIPRE Antivirus
Threat.4150696
31208

File size:
115.9 KB (118,672 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\counterstrike.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/6/2013 2:00:00 AM

Valid to:
1/7/2014 1:59:59 AM

Subject:
CN="Inffinity Internet, S.L.", O="Inffinity Internet, S.L.", L=Villaviciosa de Odon, S=Madrid, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
015B6BA30C3A5ECC19D4151834ADE49D

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:pgXdZt9P6D3XJk45VkwkQnn3UQwIAwP5k1iVr/0esmD:pe34aqV/n/bRk1usdmD

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file counterstrike.exe has been seen being distributed by the following URL.

Remove counterstrike.exe - Powered by Reason Core Security