microsoft_office_2010_professional_plus_x86_x64_en_us_final_007_[ctrg].exe

VASSANA KONGSOONGNERN

This is the setup program for CoolMirage, a potentially unwanted program (PUP) that display ads on the computer. The application microsoft_office_2010_professional_plus_x86_x64_en_us_final_007_[ctrg].exe by VASSANA KONGSOONGNERN has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The setup installer will bundle multiple adware offers during download and setup (based on the user's geographical location) including toolbars, extensions and coupon utilities.
Publisher:
VASSANA KONGSOONGNERN  (signed and verified)

MD5:
35de5178c964abbf48da3180dd9a0a7e

SHA-1:
2ec5f56c4d8db2b401323ca97c45405e63ce1340

SHA-256:
b7361cd482a7b7121604a5a5f9809b020f95a1df8e0693e91e2695b06c15d1a4

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Bundles a number of adware programs in the installer.

Analysis date:
12/28/2024 2:14:46 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen
7.11.199.148

AVG
Generic
2016.0.3238

Baidu Antivirus
Adware.NSIS.Yontoo
4.0.3.1515

Dr.Web
Adware.Downware.8319
9.0.1.05

ESET NOD32
Win32/Adware.1ClickDownload.AJ
9.10967

K7 AntiVirus
Adware
13.1814541

Kaspersky
not-a-virus:AdWare.NSIS.Yontoo
14.0.0.2687

NANO AntiVirus
Trojan.Nsis.Yotoon.deckrr
0.30.0.64448

Panda Antivirus
Generic Suspicious
15.01.05.03

Reason Heuristics
PUP.VASSANAKONGSOONGNERN.?
15.1.5.15

Sophos
CoolMirage
4.98

VIPRE Antivirus
CoolMirage Ltd
36400

File size:
472.8 KB (484,168 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\microsoft_office_2010_professional_plus_x86_x64_en_us_final_007_[ctrg].exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
10/5/2014 8:00:00 PM

Valid to:
10/6/2015 7:59:59 PM

Subject:
CN=VASSANA KONGSOONGNERN, OU=Individual Developer, O=No Organization Affiliation, L=Phuket, S=Phuket, C=TH

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7E630B1125BFC2AAB3F8750B7348F18B

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:0QquQlyC+Wr9rl/5HSD86w16OojMEb6s5/EW1ZA416xIF+OrNMfv0noCI+LfcnV:aACDr5yD8tXojMW6offAXM+O5MFCI6KV

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9397

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file microsoft_office_2010_professional_plus_x86_x64_en_us_final_007_[ctrg].exe has been seen being distributed by the following 30 URLs.

http://tornnow.com/common/custom/unibomber2_extest.php?pub=extra--banner&file=uggc://rkgengbeerag.pp/.../3760859&name=Wnzrf Cnggrefba (74 Obrxra) Rcho AY AYgbccref&fall=1&fall=1

http://www.downloadallhere.com/file_ch.php?build=ttv_setup&filename=YourDownload

http://tornnow.com/common/unibomber2_ab.php?pub=1337x&file=uggc://gbeentr.pbz/.../2P23N7N387706OSP2NPO130SO74R2SPNSQS6652P.gbeerag&name=Angvir Vafgehzragf Thvgne Evt 5 Ceb i5.1.1 HAYBPXRQ - E2E [qrrcfgnghf]&fall=1

http://www.downloadallhere.com/file_ch.php?build=ttv_setup&filename=YourDownload&rand=meBzZ8mauQUtEp2ADUTGjZdQF1nsf5kBkWbj4yuzpo23N5DrZx7jxk9dmwFCC0dWXpf1YKBn8DrWJ5nJCv2aPbncI3Ok32g1sw2qgDOphfl1kIKXdN73ZvgHy52C8jDAPG16kPvC5RDqAonNcvRb18SzdVclePW4wYaQOGtTx7k8vIVHdNTeVMO9H1vVQsZnqadeRG8pNsxjat1ogVDcHsmotRkkjjHKuVYlC7KqAhKKKL91GMdofzMIr62LqKvVFugiB1IbjsW4e55VSjj7T6QkdT5EDAAj5QBGSkSbMOf1UlXNEhVxoLSBFYgizQCEHdlzydLl10mWlkJ0BFyZqqB6pSpYJ1CqfX0NbL8dMv98PT8ryHrZ835xVuvEw85L65yhRHuDcEM2yVt6CV6KYbhUGNzcVEY2JxkAeOeqt0t1VW8xReiQqzK7mjjiXikHPEi3twuXwXZsU70LliCMSmTeGdxEvSlkxEn1aSYHPXaJ4avqs7cku5zbj7POZb9wPxx0pwHetSYy2tZvBbQ6hphBw7pwiy285A8v6QKAII9Lc8gOk6UCwcd3jCzCbBKhcTMiKwTte2eravfuCa78mkbFXLi8m3qzXcRHJLbYNqpXVFsxPzGbUSRRD900cqzaDrRmc3kZtKXpppWeZDpTvgK8qL8DbINO9FalIvkbfhAEHxTHbiBGzmP07YDiGr7P6haPNv13NCIvaBclUN1u9RugP8zvzGkGYvwL0xPNaxik8vF2iHwsy1Jn9iTJYdqXIWJJtyxE5PYelDgEkN6TPPhY8aI7o8474NQylncqdaEyOVc9Jj2y9jxhufoSosZsgQ1Bdd2roH0cCclmwoVFIsWcIl46O4z4UAF8NHzcozp1MLoj9jYRLV4ug9B4da87KOgywPKVp9WcUkv4Dt

http://www.downloadallhere.com/file_ch.php?build=ttv_setup&filename=Dumb_and_Dumber_to_2014_HC_HDRip_x264_AC3_TiTAN

Latest 30 of 30 download URLs