nov26im.exe

Couponarific

This is the instaler for an an Adpeak program that shows ads in the browser without providing information about the ad's origin. Ads are injected as banners or text-links in random web pages. The application nov26im.exe by Couponarific has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer.
Publisher:
Couponarific  (signed and verified)

MD5:
8fb2539e199bf7f894ebdb7aac546187

SHA-1:
0e0527358d10cef0f93b22cda81de174b6845c76

SHA-256:
bc85f3c1db1a4ba1f576a16295971c768297458350930dc25f7f8a8ee7769bfe

Scanner detections:
15 / 68

Status:
Adware

Explanation:
Injects advertisements in the web browser in the form or banner ads and popups.

Analysis date:
12/25/2024 12:56:33 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Adpeak
7.1.1

Avira AntiVirus
APPL/Adpeak.682992
7.11.193.180

AVG
Generic6
2015.0.3266

Clam AntiVirus
Win.Trojan.Adpeak
0.98/21511

Dr.Web
infected with Trojan.DownLoad3.35130
9.0.1.05190

ESET NOD32
Win32/Adware.Adpeak.Q application
7.0.302.0

IKARUS anti.virus
PUA.Adpeak
t3scan.1.8.5.0

Kaspersky
not-a-virus:AdWare.Win32.AdPeak
15.0.0.543

McAfee
Trojan.Artemis!071ABF784363
16.8.708.2

NANO AntiVirus
Trojan.Win32.DownLoad3.djkwer
0.28.6.63850

Panda Antivirus
Generic Suspicious
14.12.08.08

Reason Heuristics
PUP.Couponarific.H
14.12.10.9

Sophos
Generic PUA AO
4.98

Trend Micro House Call
TROJ_GE.6B9E2403
7.2.342

VIPRE Antivirus
Threat.4150696
35418

File size:
346.1 KB (354,400 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\04tb0jsx\nov26im.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
10/6/2014 1:12:43 PM

Valid to:
10/7/2015 1:12:43 PM

Subject:
E=support@couponarific.com, CN=Couponarific, O=Couponarific, L=Seattle, S=WA, C=US

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D5217FDB68336D578AC0747743835652

File PE Metadata
Compilation timestamp:
10/6/2014 9:40:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:BoGzI1XZXGGwZiQQXxQgYUNW7O19h0yuKo/yS73JRIfYjXOT54gIMZVNiTUX:Bb8XGGw/GxQDYW7c7w3J3jXOTSgP7iTM

Entry address:
0x31FF

Entry point:
81, EC, D8, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 34, 71, 40, 00, 55, FF, 15, AC, 72, 40, 00, 6A, 09, A3, 78, 92, 42, 00, E8, FD, 2E, 00, 00, A3, C4, 91, 42, 00, 55, 8D, 44, 24, 38, 68, B4, 02, 00, 00, 50, 55, 68, 70, 06, 42, 00, FF, 15, 7C, 71, 40, 00, 68, C0, 92, 40, 00, 68, C0, 81, 42, 00, E8, 68, 2B, 00, 00, FF, 15, 38, 71, 40, 00, BB, 00, 40, 43, 00, 50, 53, E8, 56, 2B, 00, 00...
 
[+]

Entropy:
7.9489

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove nov26im.exe - Powered by Reason Core Security