discountbuddy.exe
Discount Buddy
Innovative Apps
This is part of a distribution package that is classified as adware distributed by 50onRed. This adware is used to interact with the installed web browsers and inject ads and modify the default search and homepages. The application discountbuddy.exe, “Discount Buddy Installer” by Innovative Apps has been detected as adware by 8 anti-malware scanners. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
File name:
discountbuddy.exe
Publisher:
215 Apps (signed by Innovative Apps)
Description:
Discount Buddy Installer
MD5:
3e06c06ec2884c8546e10228946b6591
SHA-1:
c70165dcf183ebef367f91fe5d0aa2f5a38fec47
SHA-256:
13c173c274f6bafe969262e58368dccea60bf8fdf37e2fa9632e5822bb43bc37
Scanner detections:
8 / 68
Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.
Analysis date:
12/25/2024 1:16:54 PM UTC (today)
Scan engine
Detection
Engine version
avast!
Win32:Installer-M [Adw]
2014.9-130803
Boost by Reason
Trojan.Adw.Installer.InnovativeApps.N
2013.8.3.17
Dr.Web
Adware.Downware.1054
9.0.1.0215
ESET NOD32
Win32/Packed.ScrambleWrapper
7.8871
G Data
Win32.Trojan.Agent.R90EMW
13.11.22
Reason Heuristics
PUP.Installer.InnovativeApps.N
14.8.7.17
Trend Micro House Call
TROJ_GEN.F47V0405
7.2.215
VIPRE Antivirus
GamePlayLabs
22054
File size:
3.2 MB (3,322,648 bytes)
Copyright:
Copyright 215 Apps
File type:
Executable application (Win32 EXE)
Language:
English (United States)
Common path:
C:\users\{user}\downloads\discountbuddy.exe
Valid from:
1/8/2013 4:00:00 PM
Valid to:
1/9/2014 3:59:59 PM
Subject:
CN=Innovative Apps, O=Innovative Apps, L=Philadelphia, S=Pennsylvania, C=US
Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US
Serial number:
5419E32FDAD7A6E5666A35066C5EAAC5
Compilation timestamp:
1/5/2010 4:09:32 AM
CTPH (ssdeep):
98304:BnhpEZkSOUvJ9a0A7rEp2ol4Jx+aYdLSAWQR:BnhpEZ1J9afrko5YF5fR
Code size:
33 KB (33,792 bytes)
The file discountbuddy.exe has been seen being distributed by the following URL.