LuckySavings.exe

Lucky Savings

Innovative Apps

This is part of a distribution package that is classified as adware distributed by 50onRed. This adware is used to interact with the installed web browsers and inject ads and modify the default search and homepages. The application LuckySavings.exe, “Lucky Savings Installer” by Innovative Apps has been detected as adware by 7 anti-malware scanners. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
Publisher:
215 Apps  (signed by Innovative Apps)

Product:
Lucky Savings

Description:
Lucky Savings Installer

Version:
1.26.153.1

MD5:
0404b511d71ad089bfb1b2131d3a2b40

SHA-1:
c568b9fddece166ea81ffa3a074e311952bfb825

SHA-256:
36859ca809085dbf3ba0fd32731ca6677c6f97cabb3ca2b52ca35f18225c00d8

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
11/23/2024 4:42:28 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Installer-M [Adw]
2014.9-131125

Boost by Reason
Trojan.Adw.Installer.InnovativeApps.M
2013.8.2.0

Dr.Web
Adware.Downware.1054
9.0.1.0214

ESET NOD32
Win32/Packed.ScrambleWrapper
7.8789

Reason Heuristics
PUP.Installer.InnovativeApps.M
14.8.7.17

Trend Micro House Call
TROJ_GEN.F47V0326
7.2.214

VIPRE Antivirus
GamePlayLabs
21398

File size:
3.2 MB (3,303,024 bytes)

Copyright:
Copyright 215 Apps

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\luckysavings.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
1/8/2013 7:00:00 PM

Valid to:
1/9/2014 6:59:59 PM

Subject:
CN=Innovative Apps, O=Innovative Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5419E32FDAD7A6E5666A35066C5EAAC5

File PE Metadata
Compilation timestamp:
1/5/2010 7:09:32 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

Entry address:
0x4044

Code size:
33 KB (33,792 bytes)

The file LuckySavings.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 142-4-43-4.static.webnx.com  (142.4.43.4:80)

Remove LuckySavings.exe - Powered by Reason Core Security