obronacleaner.exe

OBRONA Cleaner

Download Sp. z.o.o.

The application obronacleaner.exe by Download Sp. z.o.o has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cleaner.obrona.org.
Publisher:
Download Sp. z.o.o.  (signed and verified)

Product:
OBRONA Cleaner

Version:
1.1.22.0

MD5:
8bdaf6278566de9ae3184692695b934f

SHA-1:
2c931979671b8edfbae2360d386ad69382603252

SHA-256:
ac0d880790ee4f6e45d8a6c85a94cd93c5b9a1d66d10524f66adee6285fde4f1

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 1:24:26 PM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Adware.Win32.AdClean
8.15.03.14.12

Reason Heuristics
PUP.Installer.DownloadSpzoo
15.3.14.1

File size:
7 MB (7,311,168 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\obronacleaner.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
12/8/2014 4:00:00 PM

Valid to:
12/14/2015 4:00:00 AM

Subject:
CN=Download Sp. z.o.o., O=Download Sp. z.o.o., L=Warszawa, C=PL

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
08883940928AE596451853B69F51C554

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:b2BXcZz4eqL5YrG2wGOLT9TUYYYDhmUaNtCA7nAZQO97ONJvKH5mqv0KL1f62JKT:bl4/SG2JmNvDxINJvKH5mqvXL1fhTzO

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9986

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file obronacleaner.exe has been seen being distributed by the following URL.

Remove obronacleaner.exe - Powered by Reason Core Security