pcoupoon_soft_partner.exe

Coupoon

This is the instaler for an an Adpeak program that shows ads in the browser without providing information about the ad's origin. Ads are injected as banners or text-links in random web pages. The application pcoupoon_soft_partner.exe, “Coupoon Setup ” by Coupoon has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. It is also typically executed from the user's temporary directory.
Publisher:
Coupoon   (signed by Coupoon)

Product:
Coupoon

Description:
Coupoon Setup

MD5:
c06a1cd122c42d1949389f2ece7a4bbf

SHA-1:
6190c7f0ba57060e5aef6835bb82e36c9ab458c2

SHA-256:
c339ffd55abb08554fb0bf16de56a29e77f10701197906c17ea6c601e633f96e

Scanner detections:
7 / 68

Status:
Adware

Analysis date:
12/24/2024 3:05:28 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.3091

K7 AntiVirus
Riskware
13.204.16089

Malwarebytes
PUP.Optional.Bundle
v2015.06.02.01

McAfee
Artemis!C06A1CD122C4
5600.6747

Reason Heuristics
PUP.AdPeak.Installer
15.6.1.21

Sophos
Mal/FakeAV-QN
4.98

Trend Micro House Call
Suspicious_GEN.F47V0507
7.2.153

File size:
315.6 KB (323,144 bytes)

Product version:
1.0

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\pcoupoon_soft_partner.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/21/2014 7:35:57 AM

Valid to:
11/22/2015 7:35:57 AM

Subject:
E=support@coupoon.org, CN=Coupoon, O=Coupoon, L=Tallahassee, S=FL, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121400C47EC899C3BA485785E2CAB2D79C3

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:a/QiQPahb5w60kOQ/UBTlakaBdGOzGfnXpiQCsoazZPElpMQgqoVJbYtD+PNi:iQiGahx0+MBTlPadSfXioRcpMXVJo3

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.8773

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

Remove pcoupoon_soft_partner.exe - Powered by Reason Core Security