cupones-es.exe

Mnlwrd

Mein Gutscheincode GmbH

The application cupones-es.exe by Mein Gutscheincode GmbH has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from static.crossrider.com.
Publisher:
Ponfhjzpatwxep  (signed by Mein Gutscheincode GmbH)

Product:
Mnlwrd

Description:
Rhcjbtqmkzblls

Version:
1.1.1.1

MD5:
dfb68b2237407a426cfaa90bad941e21

SHA-1:
0d3072ace0fc91c7f04503f536a801d70e065e26

SHA-256:
2e3e4aa29d23c84cf1ca81f4f309a8268fac12104317718b0250caa5e2970c1a

Scanner detections:
1 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
11/23/2024 11:21:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Crossrider (M)
16.9.7.0

File size:
3.5 MB (3,698,080 bytes)

Copyright:
Giddnbupxg

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\cupones-es.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/25/2013 1:00:00 AM

Valid to:
3/26/2015 12:59:59 AM

Subject:
CN=Mein Gutscheincode GmbH, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mein Gutscheincode GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6DC967C1E9C4DBE86E88DB14D51147D4

File PE Metadata
Compilation timestamp:
2/19/2012 4:01:49 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:ke6ktVYnkPxrsz4+NV2Sqq73fT1CXcyCyq6Hw5jVMndOnmzhWL:k4KnkPKzJV2u712lWyFhS

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 93, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 94, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 94, 42, 00, 56, A3, 40, 7B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 7B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 94, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Code size:
34.5 KB (35,328 bytes)

The file cupones-es.exe has been seen being distributed by the following URL.

http://static.crossrider.com/installer/31046/12289/.../49375/.../cupones-es.exe

Remove cupones-es.exe - Powered by Reason Core Security