dda2455c-3a92-243f-9c9f-cad863ece6df_1d1b8395c32e69e

PConverter

Mindspark Interactive Network

The file dda2455c-3a92-243f-9c9f-cad863ece6df_1d1b8395c32e69e by Mindspark Interactive Network has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from ak.imgfarm.com and multiple other hosts. While running, it connects to the Internet address 74.113.235.138.dub.iaccap.com on port 443.
Publisher:
Mindspark Interactive Network, Inc.  (signed by Mindspark Interactive Network)

Product:
PConverter

Description:
PConverter Setup

Version:
2.0.1.11

MD5:
921dfc6ec01b8ef47e73a3250bf13a2e

SHA-1:
f59f4c3c649280e1bb374ee265884a4f438d7375

SHA-256:
505a0e65e6d94abba253cad242470f596c3de589adc52534f9214bf8bfad7e9a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 11:41:58 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Mindspark.Installer (M)
16.5.26.17

File size:
356.7 KB (365,248 bytes)

Product version:
2.0.1.11

Copyright:
© 2015 Mindspark Interactive Network, Inc. An IAC Company. All rights reserved.

Trademarks:
® & ™ Mindspark Interactive Network, Inc. An IAC Company. All rights reserved.

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\ProgramData\microsoft\windows defender\scans\filesstash\dda2455c-3a92-243f-9c9f-cad863ece6df_1d1b8395c32e69e

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/19/2015 9:00:00 PM

Valid to:
6/18/2018 8:59:59 PM

Subject:
CN=Mindspark Interactive Network, O=Mindspark Interactive Network, L=Yonkers, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
438D4291E43C2DFFEEAAAEE5B6C070B5

File PE Metadata
Compilation timestamp:
12/25/2013 3:01:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:5bUTp1i2PJCvahaiM+hMD0KAGu+nGfMs/3Bm8jEYwUfewdNtYAjjz1dc5ISuZ2S1:5Iyk8ah00KhG//3fXBGwdcAjn1dSRT

Entry address:
0x3229

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 14, C7, 44, 24, 10, D8, A2, 40, 00, 89, 6C, 24, 1C, FF, 15, 34, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, 34, 81, 40, 00, 55, FF, 15, AC, 82, 40, 00, 6A, 08, A3, 58, 4F, 43, 00, E8, 9F, 2E, 00, 00, A3, A4, 4E, 43, 00, 55, 8D, 44, 24, 34, 68, B4, 02, 00, 00, 50, 55, 68, B8, B1, 42, 00, FF, 15, 7C, 81, 40, 00, 68, C0, A2, 40, 00, 68, A0, 3E, 43, 00, E8, 0A, 2B, 00, 00, FF, 15, 38, 81, 40, 00, BB, 00, F0, 43, 00, 50, 53, E8, F8, 2A, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file dda2455c-3a92-243f-9c9f-cad863ece6df_1d1b8395c32e69e has been seen being distributed by the following 50 URLs.

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.76e9a0cfd5ad4e33b0180ead2b3a13da.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.ab56978fd256446e95c042811eacfa39.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.1729d3382a2a458d85ffd4fc8ac50fc1.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.310328981c52401682a5bfa3254eebcc.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.42994ab05b4642c2970591820c5bc052.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.eba48207f8834ca8b1f7b346eb6c4be8.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.4b0028413dcd4be6bb3b59f57a5465da.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.e8f8e9eee29c4b4f9ae1eeb5b8f60060.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.8fddff0512fd46b1b00832c45e690a77.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.522f301f6bfd4b24a02cf1ba87dfa4b7.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.f4a2f48e911d4240b1bf7c7fbbc3c6ca.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.336a95c309e446258b9d534e5d170a85.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.176a654c12444a72b45a7a94a90e67b3.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.c4cb690347bb47498834e5d6f94aa01f.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.03759835e07942788be7a5b5a590b600.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.c3c92bbe9b4c4a199ebcf5d36814b013.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.052ee57e01a5485ea3f28c2a7ae5593b.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.9bd4316ecfda4e9d84a6168546801bbe.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.b5f857c49e0744b78a7dbf32b497134d.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.299432cca7a94f15921dfbbf4a85a2f3.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.c10aee4a6e6047b9bcc08ac010f3334f.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.8c98276af2134c4490b5b347185ccd50.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.5533dc4b4f7e4adfaa412f3822a9e9ca.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.3e06ff4024a7461c93d35950521bd382.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.f6f8a36d60054c65974c22a5c4d8ed30.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.596afb4dbad64cecad512b5d1088eac6.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.c2b5c20bc599415c976a1f257409036a.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.5769fc3d14b24b20a12a0a6d767fb451.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.e729cd8957ec47238667108c423b6708.exe

http://ak.imgfarm.com/images/nocache/vicinio/installers/v2/224203885.TTAB02.1/nsis/644583-TTAB02.1/160524180316127/.../PConverter.10e4b4d94e104fc1881bc56ac9eba3b2.exe

Latest 30 of 627 download URLs

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to 74.113.235.138.dub.iaccap.com  (74.113.235.138:443)

TCP (HTTP):