gdfr flo rida ft. sage the gemini and lookas lancamento 2014.exe

MINDSTORM LLC

The application gdfr flo rida ft. sage the gemini and lookas lancamento 2014.exe by MINDSTORM has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.netcoolery.net.
Publisher:
MINDSTORM LLC  (signed and verified)

MD5:
ef8e436efc3beed9dc13e4be2862f9ed

SHA-1:
24952b61d829af3ffbdab1011ba53019af8662cd

SHA-256:
e7ae07e5e0cf9c525f1075f1d9d51501952d8ceb3c248be3cfcc8691bce1f298

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 4:25:45 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.7.15.5

File size:
68.6 KB (70,200 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\gdfr flo rida ft. sage the gemini and lookas lancamento 2014.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
4/22/2015 6:25:42 PM

Valid to:
1/29/2016 12:16:38 PM

Subject:
CN=MINDSTORM LLC, O=MINDSTORM LLC, L=Lewes, S=Delaware, C=US

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00EA93EC087F0B61DB

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:8QpQ5EP0ijnRTXJz5Q/F9CwEdw5NeCGfK2qd5tHCTh:8QIURTXJz5uM6nKfidM

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file gdfr flo rida ft. sage the gemini and lookas lancamento 2014.exe has been seen being distributed by the following URL.