navteq_maps_free.exe

Be unique for tlv

The application navteq_maps_free.exe by Be unique for tlv has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from yes-my-lord.com.
Publisher:
Be unique for tlv  (signed and verified)

MD5:
4a1382419d1dc5ab2cb6521cf8e5ac7f

SHA-1:
5b7450fa74ca65ad2a96126f28e6aaadc19ba970

SHA-256:
ce2f35b50f5dcde17f2ffbc7ef51919c9c036612cfc4d90bef8dd302c7fad39c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/15/2024 5:46:45 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OutBrowse.Beunique.Installer (M)
16.6.30.13

File size:
584.7 KB (598,768 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Nezavisno od jezika

Common path:
C:\users\{user}\downloads\navteq_maps_free.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
1/27/2015 1:00:00 AM

Valid to:
1/28/2016 12:59:59 AM

Subject:
CN=Be unique for tlv, O=Be unique for tlv, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1CE4EDCE9C8D8BDA38A187D8D42BD65C

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:9uf9UJWNk9pXBjKau9hGh3S6IFRlVAcLpSTd3YfOPB226tuBt:90OWNScaYKS6eUASbBfwu

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file navteq_maps_free.exe has been seen being distributed by the following URL.

Remove navteq_maps_free.exe - Powered by Reason Core Security