offer_7940.exe

proZplus4.2.0.3990

4.2.0.3990ZoomWebLists

The application offer_7940.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from fingertipfeed.com.
Publisher:
4.2.0.3990ZoomWebLists

Product:
proZplus4.2.0.3990

Version:
4.2.0.3990

MD5:
5849f6fd7470135cfb34393197db1119

SHA-1:
2c614a9f3230c3322ab4e565f3dc1ea99fa1661d

SHA-256:
dbb284608ae6c70c935b69377566eb5a0e873091c1da965082cbda59a88bd7a8

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/27/2024 10:27:36 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Similagro
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.09.07

avast!
Adware-gen [Adw]
150828-0

AVG
Adware Generic6.BZUZ
2015.0.4409

Baidu Antivirus
Adware.Win32.Similagro
4.0.3.1596

Comodo Security
Application.Win32.AdWare.Similagro.EA
23189

ESET NOD32
multiple threats
7.0.302.0

IKARUS anti.virus
PUA.Similagro
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.2017125

NANO AntiVirus
Riskware.Win32.Similagro.dwjqpn
0.30.24.3283

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D[F1]
23.00.65.15904

File size:
158.6 KB (162,376 bytes)

Product version:
4.2.0.3990

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
10/7/2014 7:40:10 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:KM1BjoYNXoKDIJBXJP+j8uZRyLETcol7XjwOBfjxIDC+WcQucqMJZmNf5GbmI5fx:KMMYNXqBB+j8iRzTcu7XjwAju5WXucZD

Entry address:
0x30B6

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 09, A3, 98, 37, 42, 00, E8, A8, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 98, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 52, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 40, 2A...
 
[+]

Entropy:
7.8486

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file offer_7940.exe has been seen being distributed by the following URL.

Remove offer_7940.exe - Powered by Reason Core Security