kmpaddedcode_oppercd.exe

Download Verified

The application kmpaddedcode_oppercd.exe by Download Verified has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from 113.171.224.242 and multiple other hosts.
Publisher:
Download Verified  (signed and verified)

MD5:
3384624f8845704a8fbcfbb4a71d9f1f

SHA-1:
9ec1d38a943c2bcb95d507ff587abcea0154ecb4

SHA-256:
d32fa630b53b23ef82ab2d4e5ebaea0c44575cb43122ec89bd034b2efee4c665

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Analysis date:
12/26/2024 12:27:53 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.DownloadAdmin
2015.06.11

Avira AntiVirus
PUA/DownloadAdmin.Gen
8.3.1.6

Dr.Web
Trojan.Vittalia.69
9.0.1.05190

ESET NOD32
Win32/DownloadAdmin.L potentially unwanted application
7.0.302.0

Malwarebytes
PUP.Optional.Bundle
v2015.06.11.12

NANO AntiVirus
Trojan.Win32.Vittalia.dsmlya
0.30.24.2086

Reason Heuristics
Threat.Win.Reputation.IMP
15.6.11.9

VIPRE Antivirus
Threat.4783369
40830

File size:
655.8 KB (671,504 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\kmpaddedcode_oppercd.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/5/2015 2:00:00 AM

Valid to:
2/6/2016 1:59:59 AM

Subject:
CN=Download Verified, O=Download Verified, L=san francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
374F6915B9875363C2CF0BCF19A679AF

File PE Metadata
Compilation timestamp:
5/20/2015 7:10:03 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:j/swZgzGESxfVvWGHapIdYmS9oMBMcLgydYge+L2qMEZFI+uXBxXio58X+VoXnji:QrzGES9VWYJS9oMBpTU+NMAIDXHXi59i

Entry address:
0x1B2A

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, E0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, E8, 8C, 52, 00, 00, 53, E8, 2A, FD, FF, FF, 59, FF, 15, 50, 77, 40, 00, 68, 01, 80, 00, 00, FF, 15, 04, 71, 40, 00, 53, FF, 15, 4C, 77, 40, 00, 6A, 08, A3, B8, 34, 42, 00, E8, 8C, 40, 00, 00, 53, 68, 60, 01, 00, 00, A3, 20, 3D, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 73, 74, 40, 00, FF, 15, 94, 71, 40, 00, 68, 68, 74, 40, 00, 68, 20, 35, 42, 00, E8, 7E, 3F, 00, 00, FF, 15, 00, 71, 40, 00...
 
[+]

Entropy:
7.9740

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file kmpaddedcode_oppercd.exe has been seen being distributed by the following 4 URLs.

http://113.171.224.242/.../setup.exe

http://113.171.224.212/.../setup.exe

http://113.171.224.169/.../setup.exe

Remove kmpaddedcode_oppercd.exe - Powered by Reason Core Security