lolliscan68.exe

Installation

The application lolliscan68.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from bamba.theplaora.com.
Product:
Installation

Version:
1.0.0.113

MD5:
699ee4577a3ca4b7e8110f6fea9f13a2

SHA-1:
cb3a348f338c3dc1201b2ce2a5897b82791a9a3e

SHA-256:
490eebab9c3afcc3c4722c579dffd71d849df9d1adbc0f92123112fcfc18efa7

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/6/2024 4:52:57 AM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.OutBrowse (M)
16.12.4.3

SUPERAntiSpyware
Adware.OutBrowse/Variant
9839

File size:
721.2 KB (738,553 bytes)

Product version:
1.0.0.113

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\lolliscan68.exe

File PE Metadata
Compilation timestamp:
12/5/2009 3:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:zDMEPw1ZJ4wzJNkVsm0wvgSqPF0RiNAiL9pv4jXCv5h1GKgkOHRHqXQr0Ao4uB:z3I1cwlqsuMPF0RiNAo9pB5GKHrkM

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9851

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file lolliscan68.exe has been seen being distributed by the following URL.

Remove lolliscan68.exe - Powered by Reason Core Security