hss-3.32-install-e-550-plain.exe

Hotspot Shield

AnchorFree Inc

This is the downloadable installer to AnchorFree's Hotsopt Shield, an ad-supported VPN client that integrates with the browser. The free version injects ads in the web browser. The application hss-3.32-install-e-550-plain.exe by AnchorFree Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the HotspotShield installer. The file has been seen being downloaded from www.megadlcenter.com and multiple other hosts. While running, it connects to the Internet address 74-115-2-220.anchorfree.com on port 80 using the HTTP protocol.
Publisher:
AnchorFree Inc  (signed and verified)

Product:
Hotspot Shield

Version:
3.32.0.23080

MD5:
a6e9a5f2c91a3a3fa6f2ef7c4be63b17

SHA-1:
a6ced8edec91ebbf5d269fe3d1792be20da57441

SHA-256:
e2f3aa8cdf0576df4ddb8d77ea1f9ecae957a87163da13f188cd2250bf53848e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/29/2024 3:21:49 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.AnchorFree.Installer.Meta (L)
16.6.10.9

File size:
8.3 MB (8,718,064 bytes)

File type:
Executable application (Win32 EXE)

Installer:
HotspotShield

Common path:
C:\users\{user}\downloads\hss-3.32-install-e-550-plain.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/27/2011 6:00:00 PM

Valid to:
4/13/2014 6:59:59 PM

Subject:
CN=AnchorFree Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AnchorFree Inc, L=Sunnyvale, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
68A4A0CC448443C288A22A91D7F82126

File PE Metadata
Compilation timestamp:
9/9/2009 8:22:54 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:ITHY1iP025H5T++OIFvsnx7J1JySPHnlN5NRbRlnhNGqlgvcspVvkg2b:IDYG025HLOWvsj1JySHnlJNRmJvo

Entry address:
0x33FF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 70, 85, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, B8, EE, 7E, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, ED, 7E, 00, 8D, 44, 24, 38, 50, 55, 68, 6C, 85, 40, 00, FF, 15, 80, 81, 40, 00, 68, 54, 85, 40, 00, 68, C0, 6D, 7E, 00, E8, 35, 26, 00, 00, FF, 15, B0, 80, 40, 00, 50, BF, A0, F0, 83, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Entropy:
7.9972  (probably packed)

Code size:
25 KB (25,600 bytes)

The file hss-3.32-install-e-550-plain.exe has been seen being distributed by the following 32 URLs.

http://www.megadlcenter.com/8TlwHgFhNu0lJKyRzMsESiPgyBqztqxBp5DkgvFoVYn1LOjiTLRGOKtVEOTB8 _NfivKeOe_A1tV4Zgpa3uxxOBabMczR4EgTA1r0P69XWe7SKbqfhu2r0a2rNakNw8LnhL SBoVPqGEEItqNe_h1 J_nRVykNNPgyVpm9ciYIsgBMn_0IonDebY_ EzOdepx6_9OgHijQeKIZ21ucRvYqwrnA4ZVQoTQTyieqIP0gX6Hmg_DvJmTUuRUlsAqHcP3Th6IBKirwOUiDJA4aob3AuRTfXb3oIVBJFeGAM1T45rCzqVQrDZqtAV32Y0VJdnhYLi2fN8ujFWBiwEhb7kuhdCXaCHB0ZEj8C8KjYqlu4 quCON9hR1nSLC2Jsx_YpF9998B4nup8wTDKfz_G7oIO16a2MVSvYY1Z10ubSf6tGs5rNYhb5rkRbIAqjnQn3NWTHfSjEf4abl7JjZndSqb3rS8lgIsr3a8a6d2BtKmrW yQQpjugrTWz8koBiZx95rF8UZJpKVXZZLWAi8OwpHp fxSD70SjYt8bMfvFjQNeVRlvFz8=-G1MAAMTcRjHdJo6Fbl oHigIf9AxDnUAv0HPB513HDyGz7NDSXy0xt5Lim54bwFt8901uK1zVK3S5dESARPLwA3CPSH3CD8B-e

http://www.megadlcenter.com/Swsuz825vQ1p87Zyqd2Ci2sm1ywTFQCFwab07 hnUquZ4RRUIOoAoKfKkyjtE7GvgJGvDk481kSZhZDY6GnmdzHCXbWhzrdbKcsCfW9MIC6LiUIMnRMMCAHhLYcLdHyo6CDT9kyyzRqibJrOpTb2pP2to7 XxWkkAOCuCPYgAvSjsbCcl099b6qvJQHbFukt7OpPjdGQMzNPvZFrLxrhIEswIcmwxEaRrJfcF1D_WD2JruFm9cPqbg6NQfxp0KCJTCuuCbbQgNjw_dpG1SFCrWzp3c6cfSfTHYS9EJgGUaehx1aawVUhewdA6FYdeBhSjTKxWJwVio8OpagfTO7gjjw0LcRVyNdAC6zhc5Wlhw4rFd0WItDGzKQ1TAVXUUSICqDpB1oTDF_V7SMjAXKMZsWzxKdbu 4gwCW_TrdENsIBG Y9YHc4vCo AfOb2W8nuJ0RSo_HJduM85L9Kw0pCefb0zN9_5inB2TOjJWh_sbVed xgWMhuFT7hBhdVtys0tWTJg8KM8F2bKc5ln9_gh0qT48AcDgdcPLJcDT8P4WR 7jp2cE=-G1MAAMTcRjHdJo6Fbl oHigIf9AxDnUAv0HPB513HDyGz7NDSXy0xt5Lim54bwFt8901uK1zVK3S5dESARPLwA3CPSH3CD8B-e

http://www.megadlcenter.com/duEqXfEfBsjkHLImkY46byYwhgZjyyHI1IOFWzvIRcWtZkwSERD4M53 wQ1Zh7Zzml2SvwvV9UmptguMWFyMx2gHi7aswTAFPnB6p9KYGyDZmVzLBUApBLAudYs54bnxRCL_6y4u1hlSKtHY5bJFsdc4S3wFFSRm0T zx_eh5pNfEK__qXAV8xUsGPsxCMcClax5kLhYtQW_4lWdnNdpVMca7vIrFRJoYosLbesaS_0YpIecbeguQPNmFPfV6nu0gZ9LdbaN6nYKeFGjwJhdPnfMmXr hsFwiL79N6DWW5oVjpATe3sU15X2l5V9Jj7188vzU25zxPLqTzaiD7J1anCpHuTU_SVPQ45tbmnzPgGMWUKmO0zoJIy7xSJ7VNxRakMVK2BjWyaliUhjQVvQnSCb0RO6m818oLfQg m115J87SK5ebtWjl3QHvncJVZ1grzzei2mu9qn_O5HOlL3JWRneK0jtroXynQVSuk9Jq0e IzVP4OgTPzhhsnrugjrtH1sif6fTa2D7w2dBWICq1dYYZszy31tK2t8uXlTKxvESjPfEGA=-G1MAAMTcRjHdJo6Fbl oHigIf9AxDnUAv0HPB513HDyGz7NDSXy0xt5Lim54bwFt8901uK1zVK3S5dESARPLwA3CPSH3CD8B-e

http://www.megadlcenter.com/LMjkEicU1X_dOUI0zfHrsX_GSa6mlixgOjgK9mx9Meof9JQNv3vkzBGnxdIQ7CW6xQcqnDKgGo4Yp6cT_AmCGdvw n8eAFp QI1QntTm7EmFgVXMsi9MCyEFraDoOVC5Z 7330afvJbJj3KL_ePEsKpS yIgZc9NJ5_xRNpL1TGuUKNywF29oDZbV5K8q_IZONuAkrVjC j1_jHpFN1v0UNmQW4RdmzZK6Rss2IFTUqbhRVQujwV6e yWLmWjQhWhpUmfpwV5aWIqMwN1vP7jcgVETv7qWsh5AgfqZE x97xwtWNHpG2GEDMWu4loVIwtNgvBg xlnMy_sZsSTirjOX8qOhwgy_PZi fvPb_XOOJ7ZoQIKnNRAqmJ1urlGsVUorDROa_wB_M2EV2yJu1KUqYh8iWHtSLlgLSgd3EXIJS4a9ASex4 DXEFivPUDL3uwAXOOOKliJaB7K6voxnNY7P8L0U2sLvq0JCcfN9J4mqJoH3NET2Z7czOmMvLXUU61LdESVB7AXA39l1iAb_CYAdnExfqkSJ3N5t5Zt0axqoXN3IgWU=-G1MAAMTcRjHdJo6Fbl oHigIf9AxDnUAv0HPB513HDyGz7NDSXy0xt5Lim54bwFt8901uK1zVK3S5dESARPLwA3CPSH3CD8B-e

http://www.megadlcenter.com/RUthAK6apZjLUOS_GyS6H3kUU1YENIizMg9LlUT8U8N2QD2cRI8B1w0_PWeqQl1KoORfU JZLrTuDnRo1E2qZuccd3Z3aYSAYcw26Gawgejcyn82sUuUSdKtXd7 cmzhlC2 8 FwheMZXU5G7jum2RIW1bXh_ jQYhTw0YjlNEAwiv_5cY6aGge0PjFG1VFSxKpNtPiO81hxdUta1L959U0 3vZO6A==-G1MAAMTcRjHdJo6Fbl oHigIf9AxDnUAv0HPB513HDyGz7NDSXy0xt5Lim54bwFt8901uK1zVK3S5dESARPLwA3CPSH3CD8B

http://www.megadlcenter.com/BIEV1v3mvyg4nGZmPq53 qWDlsGxVe0lDmGzSgJGH1gKztxSdnQwxAXjSio39GdQLVtC2Gb9nDV8zJh93RY4PEuVVXs3eXoN3uvPLYjZ54mbfNesX1vrbgCuXXhQMeGwmTvdAqT_wxXt60Y5AngIUTc SyO0T4cQUjNCpD8 arPUamZK73WVo3_NaKNhzh2k9Wi009MIsoosntV8FPcv8RQ7Y1bOreZOsJX29Yg9jlksO S9fOVss1sCt0d E21xBhU7qbeYknlC7zMfEE5sNhuCAm3W1stuMON58pfCkwJzOReIz 6AyYsXo4KWSv_PR54Aj5nrEGOV4zFFzNdM_1BAA9GKiOBop3ADQb5bknU8gC4YIeb 5MaCo ey5OJUQCyhWFXS_5T3alfR0o2m5h_qo zt5VAr8K4hxNasBoRMd8A1oYNLjeYygmNdHjg9r70xjQw4WHWzT Gc_3ZsIX81qQohcj5u3Rfc8GYH6MorBFexvmG8cZuxXGdOaEWXBjvPvc19u2FgnPaDua5yjfxPzHQeX2nUpakr1wE_DNabxD njW0=-G1MAAMTcRjHdJo6Fbl oHigIf9AxDnUAv0HPB513HDyGz7NDSXy0xt5Lim54bwFt8901uK1zVK3S5dESARPLwA3CPSH3CD8B-e

http://www.megadlcenter.com/wPLQZE_lP50Xt91VcCEaS2Tl2Mfrq3LqP_kov7AiTlrgY iMOH_2dh4pG7sY6kIWsIIywXQhOBR1 FyAI2t1jTh9vlHKGx4UsQOPgKksC1q QYkb2iGWkgouSulf_sqyY kmF0os_Asr06qVS3fUBWzSyBMsp8rSLYO4i_mIQmrb0nYiHu8257akrpJ4VD8RaELz3n8xdJRTyg piGzYciVlSPvebYmJSveJVVUm_ZRAVz8 KpJFFh_ifA0N7TzZ9xeE6qZFMQexroVlNlz6yT1McfJucyODZkhN7MVy3RzDLjDtQK0 JCSnUR tdKeO078iFWLcOS93fl9bXvJ4SLcFWL4x87VPyqS4kEs7Q0oKauLDzQWdrTyANADQXKtDAIaI5fbyBxWJzy1rJS51nUGuRwhZxv4BNEAtRMo80p1J3zt12WYuUohcgj0axWfVuUoH6WMgIrljHjGVsDM T4tg5TAeovUPk6IJkjMo5oZgzfQK6BdnxUN1maHjsJtlgW80MaYGhhoQmIkJZ QDTr4WA0JLFg9Jaq0lMcIwT7eNx7Ezg0A=-G1MAAMTcRjHdJo6Fbl oHigIf9AxDnUAv0HPB513HDyGz7NDSXy0xt5Lim54bwFt8901uK1zVK3S5dESARPLwA3CPSH3CD8B-e

http://www.megadlcenter.com/PwYLNuXsjTHVY3CmoYrSrow43WBnqGvyCuOUKqHzk5jaKYUcXybIBCt_7EAQGJjECVCRws0cx9Sk8sMtYkDkP1hc487sZnY1mdRr3dmq9sshnEuqUoZLteY8OFg_XXFmsgK9F1qcqhyPCXYm0Tx9FrcSREqC6QttXOo yZQlSESXWlsHgNkBcVGu IZUVC_yxBtTwb Cypezt2WC7qYvjKfWYhPLRzkDBHAkVAfDD 6kRZmSLm_XYb8yGmAVtJUy1WkadrnwVOKL986PkUANT4Uf4jhEE5Ug3Lq8UyCuqxK8hdGj04o9gfxMrVTNdSSyHSpoHa0xWeWZaLvZRi MHOJOYrZK0dEq0YGEQ SKiHZrNzXrskOW_8leqyxSRiSlXQguYjyPG2sKVioWXrBt_whAH9N8PaMQStBmPVR6JUzoqSNqLwwghTKwLgngH139443ueXqiDuLSD9qDMuh_GCD5Vixhdupk7 1sNxAVZOKFWw8SwI4cE4N6GTlgTHMO5lx13NfX8PpejGxEwlZZw8pv3a1r7DOj39XEk9bjbF9Bznb_5PA=-G1MAAMTcRjHdJo6Fbl oHigIf9AxDnUAv0HPB513HDyGz7NDSXy0xt5Lim54bwFt8901uK1zVK3S5dESARPLwA3CPSH3CD8B-e

http://www.megadlcenter.com/sKPiHbOTVRTbfiTr3k_9N3bUU9BpVL4zKS39R2CfTV1XHUfOK7h4oLtOo5XS7tm6LMn8RbnvFf4qOd x0xLyZSlWfLccyEfjSVmkvcR2jdiL_urgtAVbDDg KZhzLKSX_nuKtNeS0STdZHTwC9j0i6ReD F0Pvl7l7cyx7jyi5zXXKVqgHEjXjCgr2RD_uqek6vGrtTvt68YwutnYft42QEEC1euRHg9azlurD6sLpUFG o ChcNONpYb3ML_VRa2gFqwyt gcxi77iw1y8gdw9_ggql_anJzYLY2CvM5Ykky1xFPyREu9yfKdJwTzlD8wFvISn 7QHLaMvSHzSOPM8PeDMDoGuUP0asNBLIXZq6_wE2PxdBUTI5bNq1E7rc8 tD_DVZ5V_imPUNGtvDwcaEKxx72LVptNxXmPCYLmSiUxPwfYNwOD4iSKQOuU4Ww9499nMUvHKbBAguWVOgH1b99VWzq2_ZFynOWSPPFG2x5bbDxcf6Frk9aGiVF97BDUx0v g_MDREvi1EowgvnxiZ7nZgT94i8ZoatjITJDzwmYm0GxI=-G1MAAMTcRjHdJo6Fbl oHigIf9AxDnUAv0HPB513HDyGz7NDSXy0xt5Lim54bwFt8901uK1zVK3S5dESARPLwA3CPSH3CD8B-e

http://www.megadlcenter.com/AJqxKqJTigmK9yDMy0KTM_ UYZjTYvpsLhGeBNyE4Ggt1YpEwv0zLV4t_wl6jbfgdNhBuiTRS6JTcivBHGvI9KbCaJSdPpMs gINCdOvonqSgNZHOT02tO5ICG3XoYnM7GM_AwqmOvP5RiHVEhq09xDtlGh4NPdEQ034MO12dqWmMfgaJc8VBPa8LOTmNU1I_flvQNVYVSbWxmEg9Klxi4 xXxnZwLnIABczdz3nA M 0t9Kf0XfDGxvRl1mJyweDS41GN YdjLYLvrBrXalQv3xgdtOSd3ug1JzdIeodgDfWrcZhalClY7s3myDs3J4QX3PocvccXmIVi5cvBy1EjarBJu7phpHSDmTn5ihfqW F837_Oy35rEGgVRdSRYri1nzebPLEQiWygJcwPBBZbLaSkXJIgN4MSJpOGRATmaHbOZpnPs8C t_IoKI2uR5dKBMiSVymI8paZAKLDYckdMq tu0j6urZW _9qUTezI9Ee7AcufM6i_hJ1h4EynFGd1YNV5m4s7cfZ87tCEsu_AVi6NV98luUcf9UcqWkq8tOQ8gMEo=-G1MAAMTcRjHdJo6Fbl oHigIf9AxDnUAv0HPB513HDyGz7NDSXy0xt5Lim54bwFt8901uK1zVK3S5dESARPLwA3CPSH3CD8B-e

http://www.megadlcenter.com/Ws7ZAciB8uqOmq2 5w9H2VXxDdYjovwVjwGIQ94ikaZOqp2iR401_7Pb9MmlMVxO_bFES4hn6lA38eGyYIwyw43VJN3g rEu57cmJ1d1sXFYLsG2QXE58fE54wAiaIciHFzK2UccuaamhQGaqhM7q4e5H_KKho3Ybgse2_H_HyWt5igck3QJGdMtPq4O3dAM60i10dlNic5O8nsOnLQb8 OeiBSfIIa0ukB8ZI_6gN6ko V1T4_IKc0NHJTvFnlR f9fqgPB_uvUMcXp6pBmsaHUsNP_rLzhudp0YE1gRgQpYd fr6JaAnxUUnq4xR5LDAUgbsIbK9 Y4JKMhSVodsRsiApsLfJk3QHYMsB4nj2S CUNpY4b28IAZLjD9NSe1avFMyCafddBpj LxTWsDahJagIv4XCvGnAe3zIAyIwzpZYJHQvtIe2AyqbkPV9ALPVvGfbKL3iWBImFOMQGlRmYKlNced9Zr1dysqwHEwQ4mMucHM04_Jd2NXiaHb3EGi6kYZGuSlF6e35eJpz4foW7af6eI1XZX4Io5taOft8adzDBTU0=-G1MAAMTcRjHdJo6Fbl oHigIf9AxDnUAv0HPB513HDyGz7NDSXy0xt5Lim54bwFt8901uK1zVK3S5dESARPLwA3CPSH3CD8B-e

http://www.megadlcenter.com/OIuz0GOujWagBDlIWYT_oL29QE7FMWcbEuIbU559gDKlIgRRYr_co7zIOxEK8bOdbL4VUxNsstj yU9UBT0ttfVtcZhEkmt8WjW55EdNAt30k p8dCwBsjgrltllB2YjoBzqXisp1Dhe99dbYSBaW2NSikM r6MaF8ghz26RIsLwWAXIjywluuBiTbvxgwEx3Z_5nkxf5AAfEyr93hjnDLh9JCb1VkgvjGdDnhIV5GyWCpfQFffHo8ewuW0F 1hUMTQu6I2t pcKe2KmUiAZk0Ct7U0FmXzN6dH7lbB36O1pqGURFjjSCcdY6zBDvINjKlpU1bRkKzgkPgCC6M9TGPWGb99p9B0uj3ANyLpSDqNeAcklTeiLH2B2yDmxvXPPF2C7_pk2UxuzVhzWsWMf0UW5xBbJjEEowD8QeoO4yTDIPpWt0EMX002vJNs5Zx8gj7Q 4rMAwwCkq c1XxAONrfeyq63dIz4eURqZqEwG9OWuvyCNCIPLsusOCsDmyaDiCnnf9qw5hfdV47k JJbC0iavd91sEpc5cTJTdeuZ1cqkCbE6_0=-G1MAAMTcRjHdJo6Fbl oHigIf9AxDnUAv0HPB513HDyGz7NDSXy0xt5Lim54bwFt8901uK1zVK3S5dESARPLwA3CPSH3CD8B-e

Latest 30 of 32 download URLs

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 74-115-2-220.anchorfree.com  (74.115.2.220:80)

Remove hss-3.32-install-e-550-plain.exe - Powered by Reason Core Security