LuckySavings.exe

Lucky Savings

Engaging Apps

This is the installer application for a 50onRed advertising supported software package (displays ads in the browser and may hijack the home and search pages of the web browser). The application LuckySavings.exe, “Lucky Savings Installer” by Engaging Apps has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Innovative Apps  (signed by Engaging Apps)

Product:
Lucky Savings

Description:
Lucky Savings Installer

Version:
1.29.153.2

MD5:
a6b615382535668254e26ef3962e3b21

SHA-1:
790fffd5c45cad5ab6444a37a41c56fc543e9e08

SHA-256:
f44dd66c3f67f4d8de983c6f29f444d418a6cefeeda56788c9b6714d7acc806e

Scanner detections:
3 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
11/23/2024 5:06:20 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.Crossrider.10
9.0.1.098

Reason Heuristics
PUP.Installer.EngagingApps.M
14.8.7.21

VIPRE Antivirus
GamePlayLabs
23318

File size:
3.7 MB (3,902,304 bytes)

Copyright:
Copyright Innovative Apps

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\luckysavings.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/3/2013 8:00:00 PM

Valid to:
6/4/2014 7:59:59 PM

Subject:
CN=Engaging Apps, O=Engaging Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
632EEBD9B987BC680D444D8675A26545

File PE Metadata
Compilation timestamp:
2/19/2012 10:01:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:acjtgBaXr74EBL4gtKMd4vUFM++HuJRKJUSeB4lS/:T8mrsEOgtPd4vUFiuJRKJ8Byk

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 93, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 94, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 94, 42, 00, 56, A3, 40, 7B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 7B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 94, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9944  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file LuckySavings.exe has been seen being distributed by the following URL.

Remove LuckySavings.exe - Powered by Reason Core Security