limewire_ultra_accelerator_free.exe

LimeWire Ultra Accelerator

Hipgnosis Vision

The application limewire_ultra_accelerator_free.exe by Hipgnosis Vision has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.trafficspeeders.com.
Publisher:
TrafficSpeeders LLC  (signed by Hipgnosis Vision)

Product:
LimeWire Ultra Accelerator

Version:
5.4.0.0

MD5:
c7581fe590ff83992f997678ef7adc53

SHA-1:
592197c43ffac874f991f016bf215dfb08ff6f9f

SHA-256:
16b41c969f8e5d3d59914e883361976f38cfd3055c152c905dc9845c514cb8f1

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 4:56:08 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.10.24.19

File size:
709.1 KB (726,136 bytes)

Copyright:
� TrafficSpeeders LLC

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\limewire_ultra_accelerator_free.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/10/2014 10:00:00 PM

Valid to:
3/13/2015 8:59:59 PM

Subject:
CN=Hipgnosis Vision, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Hipgnosis Vision, L=Craiova, S=Dolj, C=RO

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
67706B72437E415E8AB76B9C4C85261D

File PE Metadata
Compilation timestamp:
2/24/2012 4:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:xEsVY5pmPtc+4rPyve/DNVnDLT4TR/vZCPn0LkxWySFkWY038iC2/bqEWXEN1U8:xBVYeG+4r6vSUvZi0gpvRcqEWXE08

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file limewire_ultra_accelerator_free.exe has been seen being distributed by the following URL.

http://www.trafficspeeders.com/.../limewire_ultra_accelerator_free.exe

Remove limewire_ultra_accelerator_free.exe - Powered by Reason Core Security