lly1_istartsurf.exe

4869_tug1_istartsurf

Thinknice Co., Limited

The application lly1_istartsurf.exe by Thinknice Co., Limited has been detected as adware by 8 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from d2drfrdurj6mvo.cloudfront.net.
Publisher:
Thinknice Co., Limited  (signed and verified)

Product:
4869_tug1_istartsurf

Description:
Installer Module

Version:
1, 0, 0, 1

MD5:
15944a15e5faaf23716a3e716dec313c

SHA-1:
39d78a45b47aa31463037afe98991ded3f86bfd9

SHA-256:
488661f5381598679d185ec20a0895c43687b96c7a09d5623f6e4d65b7a9d9d3

Scanner detections:
8 / 68

Status:
Adware

Analysis date:
11/27/2024 4:35:44 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Oncer
2014.9-151007

Dr.Web
Adware.Mutabaha.731
9.0.1.0272

ESET NOD32
Win32/ELEX.FK potentially unwanted (variant)
9.12327

F-Prot
W32/Thecid.B@mm
v6.4.6.5.141

K7 AntiVirus
Riskware
13.210.17366

Malwarebytes
PUP.Optional.IStartSurf.ShrtCln
v2015.09.29.03

Reason Heuristics
PUP.Thinknice.ThinkniceCo.Installer (M)
15.9.29.15

VIPRE Antivirus
Threat.219451
43798

File size:
536.1 KB (548,984 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright 2015

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\lly1_istartsurf.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
9/25/2015 11:18:26 AM

Valid to:
10/21/2015 9:26:52 AM

Subject:
CN="Thinknice Co., Limited", O="Thinknice Co., Limited", L=香港, S=香港, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112170C8A859FAC5632237A13A696FA39819

File PE Metadata
Compilation timestamp:
9/11/2015 11:27:29 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:/TwsAln1giCPA6W8XHFlrZtTVq2QBOiVuAC91hrrrrpo:LDbPW+pZtYlBOigAC91Ho

Entry address:
0x2E557

Entry point:
E8, C7, AD, 00, 00, E9, 39, FE, FF, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 85, FF, 74, 13, 8B, 4D, 0C, 85, C9, 74, 0C, 8B, 55, 10, 85, D2, 75, 1A, 33, C0, 66, 89, 07, E8, 64, 27, 00, 00, 6A, 16, 5E, 89, 30, E8, 04, 2E, 00, 00, 8B, C6, 5F, 5E, 5D, C3, 8B, F7, 66, 83, 3E, 00, 74, 06, 83, C6, 02, 49, 75, F4, 85, C9, 74, D4, 2B, F2, 0F, B7, 02, 66, 89, 04, 16, 8D, 52, 02, 66, 85, C0, 74, 03, 49, 75, EE, 33, C0, 85, C9, 75, D0, 66, 89, 07, E8, 20, 27, 00, 00, 6A, 22, EB, BA, 55, 8B, EC, 56, 8B, 75, 08, 85, F6, 74...
 
[+]

Code size:
344 KB (352,256 bytes)

The file lly1_istartsurf.exe has been seen being distributed by the following URL.

Remove lly1_istartsurf.exe - Powered by Reason Core Security