f_0003cf

VASSANA KONGSOONGNERN

This is the setup program for CoolMirage, a potentially unwanted program (PUP) that display ads on the computer. The file f_0003cf by VASSANA KONGSOONGNERN has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.getmydownloadsnow.com and multiple other hosts.
Publisher:
VASSANA KONGSOONGNERN  (signed and verified)

MD5:
cbf0df53f3bbf50aa40d95a463926ae0

SHA-1:
b95adeaf701fa024b963a6d3ffb0db994adb8260

SHA-256:
3e48590b2631524400a42091a9910e4a3cebbedb65b7d43fc79833ac16ba62af

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 2:19:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.VASSANAKONGSOONGNERN.I
14.12.16.10

File size:
75 KB (76,776 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\google\chrome\user data\default\cache\f_0003cf

Digital Signature
Authority:
Thawte, Inc.

Valid from:
10/5/2014 8:00:00 PM

Valid to:
10/6/2015 7:59:59 PM

Subject:
CN=VASSANA KONGSOONGNERN, OU=Individual Developer, O=No Organization Affiliation, L=Phuket, S=Phuket, C=TH

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7E630B1125BFC2AAB3F8750B7348F18B

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:VQpQ5EP0ijnRTXJiw/Md3yCN+RgEfDGM0U0KV6:VQIURTXJjEd3yC8giDGM0oM

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.2181

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file f_0003cf has been seen being distributed by the following 50 URLs.

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wRRAGU2UJQ1SLTMG0G7SABBQ

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=w5E2I97G1C1LUSLG0OIVD2NS

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wP754ASD1G79JEKGG2DMSP7E

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wLQAG81LC7FLQBLG0NS4FDFI

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wJTP8D44SBOCBQVG0VHILFB8

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wPUOJJ8O7HQP70LG0EDRNO5K

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wJAS9UDK0VU4G1OGGBCN7JI6

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wKG42ONMK2VMPBHG02AEHK64

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wDR09E9KKT0D51LGGK60JMEM

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=w042EVLS9F7DEBNGG0GS3B5P

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wG3EHEIRDO8903SGGJHIUU44

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wSP12E2EBSVQEJRG0S8L565Q

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wEPUGNGCN0A40DMG0TDAIQ1I

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=w37BREQV7UEOVVRG0ROURU0O

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=w9C2K2CESTMA5DMGG2OGG6KK

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wAC10ONVSIHPTGJGGVVGVV0K

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wVGV8MAJTF3SRDMG0K0AK932

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=w015T7FDMF5O02LG0U8Q242D

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wCCSUMT3G5F5COTGG0O6QB02

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=w0M24OFIL21B1MRG08HAU78O

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wD62C637D113IJMGGKU5CJ3O

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wTO1D3HT5HH4LUMGGE7FQHAO

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=w3AE9R7ENC91KVQG0NHMI4IC

http://www.xflv-player.com/.../mar7.php?subid=marmarlk&sid=wAHL98QU35A16HMFGVQU27L0

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=w30H4ITURTGRMNKGGLMP48AO

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wNCAOQSN77TVJ4MG0VSUR8K0

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wDIU38CCO90RLFOGGAGC4A3G

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wJE44321PL6IV2PG00N9GCFC

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wN87RP7PBIHUR4LG0V76AJ66

http://www.getmydownloadsnow.com/.../mar16.php?subid=marmarlk&sid=wKGN70NMC53RP6NG01DRNU7A

Latest 30 of 548 download URLs

Remove f_0003cf - Powered by Reason Core Security