offer_7940.exe

proZplus4.2.0.4095

4.2.0.4095ZoomWebLists

The application offer_7940.exe has been detected as a potentially unwanted program by 20 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from fingertipfeed.com.
Publisher:
4.2.0.4095ZoomWebLists

Product:
proZplus4.2.0.4095

Version:
4.2.0.4095

MD5:
9dde05455b9b715558d49bf298badf69

SHA-1:
68a4f660190a640d76b3c448955ef6b182a0e486

SHA-256:
c65b22c28c457e4e514b4b1ed16c85843964857d458b1bd94edbfb69259f663a

Scanner detections:
20 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/27/2024 10:46:38 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Mikey.23752
509

Agnitum Outpost
PUA.Similagro
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.09.14

Arcabit
Trojan.Mikey.D5CC8
1.0.0.526

avast!
Win32:Adware-gen [Adw]
2014.9-150914

AVG
Generic6
2016.0.2987

Baidu Antivirus
Adware.Win32.Similagro
4.0.3.15914

Bitdefender
Gen:Variant.Mikey.23752
1.0.20.1285

Clam AntiVirus
Win.Adware.Similagro
0.98/21511

Comodo Security
Application.Win32.AdWare.Similagro.EA
23230

Emsisoft Anti-Malware
Gen:Variant.Mikey.23752
8.15.09.14.08

ESET NOD32
Win32/Adware.Similagro
9.12247

F-Secure
Gen:Variant.Mikey.23752
11.2015-14-09_2

G Data
Gen:Variant.Mikey.23752
15.9.25

K7 AntiVirus
Adware
13.210.17197

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1428

MicroWorld eScan
Gen:Variant.Mikey.23752
16.0.0.771

NANO AntiVirus
Riskware.Win32.Similagro.dwjqpn
0.30.24.3283

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D[F1]
23.00.65.15912

SUPERAntiSpyware
PUP.Similargo/Variant
9630

File size:
158.6 KB (162,372 bytes)

Product version:
4.2.0.4095

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\offer_7940.exe

File PE Metadata
Compilation timestamp:
10/7/2014 10:10:10 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:KM1BjoYNXoKDIJBXJPkJj8uZDyDAMp7ogentDNwWmKtsml/so/saTzxRTuv2Q3gw:KMMYNXqBBkJj8iODAot6NwiRmMd4+6T1

Entry address:
0x30B6

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 09, A3, 98, 37, 42, 00, E8, A8, 2D, 00, 00, A3, E4, 36, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 98, EC, 41, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, E0, 2E, 42, 00, E8, 52, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 40, 2A...
 
[+]

Entropy:
7.8488

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file offer_7940.exe has been seen being distributed by the following URL.

Remove offer_7940.exe - Powered by Reason Core Security