offer_7940.exe

proZplus4.2.0.3930

4.2.0.3930ZoomWebLists

The application offer_7940.exe has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from fingertipfeed.com.
Publisher:
4.2.0.3930ZoomWebLists

Product:
proZplus4.2.0.3930

Version:
4.2.0.3930

MD5:
d42e064946a6ee1e471b5ea7debcad57

SHA-1:
4347a18799d6add28e7832a615c96cfaec3b003b

SHA-256:
a1f9357d23da1cdf45bc90e1721af2814e8b3e8d3395813a87c7f3424939a882

Scanner detections:
6 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/27/2024 10:35:03 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.09.02

AVG
Generic6
2016.0.2998

Baidu Antivirus
Adware.Win32.Similagro
4.0.3.1592

Comodo Security
Application.Win32.AdWare.Similagro.EA
23139

ESET NOD32
Win32/Adware.Similagro
9.12184

Rising Antivirus
PE:PUF.Similagro!1.A0AE[F1]
23.00.65.15831

File size:
158.6 KB (162,409 bytes)

Product version:
4.2.0.3930

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\offer_7940.exe

File PE Metadata
Compilation timestamp:
10/7/2014 7:40:10 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:KM1BjoYNXoKDIJBXJPFj8uZLWGwz8WojEovLzIOJP+6ij9Zie3HD7tYQjH+a+uAi:KMMYNXqBBFj8iaGwzw/IOJ2j9ZFll+O7

Entry address:
0x30B6

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 09, A3, 98, 37, 42, 00, E8, A8, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 98, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 52, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 40, 2A...
 
[+]

Entropy:
7.8488

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file offer_7940.exe has been seen being distributed by the following URL.

Remove offer_7940.exe - Powered by Reason Core Security