pm.exe

Price Fountain

The application pm.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. The file has been seen being downloaded from cdn2.chironexfleckeriolive.com and multiple other hosts.
Publisher:
Price Fountain

Product:
Price Fountain

Version:
1.1.1.5

MD5:
211490ec3b5e3fc9c71090b5a45f5f89

SHA-1:
9f302f2f7c273d08489b76cf570d04928783eb31

SHA-256:
2464e058fef552806cc77215162f3e03a8b8dc0dd264abefe067cf867993354e

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
11/2/2024 5:29:35 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Barys.9880
581

avast!
Adware-gen [Adw]
2014.9-150514

AVG
Adware Generic6
2016.0.3059

Baidu Antivirus
PUA.Win32.DealPly
4.0.3.15329

Dr.Web
Adware.DealPly.9
9.0.1.0184

Emsisoft Anti-Malware
Gen:Variant.Barys.9880
8.15.05.14.09

ESET NOD32
Win32/DealPly.AC potentially unwanted application
9.7.0.302.0

F-Secure
Gen:Variant.Barys.9880
11.2015-14-05_5

herdProtect (fuzzy)
2015.7.3.22

Kaspersky
not-a-virus:HEUR:AdWare.Win32.DealPly
14.0.0.2271

MicroWorld eScan
Gen:Variant.Barys.9880
16.0.0.552

NANO AntiVirus
Riskware.Win32.DealPly.dqbhhb
0.30.24.1636

Quick Heal
PUA.DealPly.01517
7.15.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
15.5.14.17

Sophos
DealPly Updater
4.98

VIPRE Antivirus
Threat.4150696
39676

File size:
2 MB (2,101,248 bytes)

Product version:
1.1.1.5

Copyright:
Copyright © 2015 PriceFountain

Trademarks:
[12345678] [default:default] PriceFountain is a trademark or registered trademark in the U.S. and/or other countries.

Original file name:
pfinst.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\0846756a_stp\pm.exe

File PE Metadata
Compilation timestamp:
3/26/2015 12:59:20 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:lxcVMrVQ7bLzjufxLKZ/KH5FqW9Yjk4wKm9YYYd:lxoMhQ7jZCZFHYjDwKQYYYd

Entry address:
0x93936

Entry point:
E8, 5C, 7B, 01, 00, E9, 35, FE, FF, FF, 55, 8B, EC, 8D, 45, 14, 50, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, 5C, B6, 4A, 00, E8, 60, 00, 00, 00, 83, C4, 14, 5D, C3, 55, 8B, EC, 8D, 45, 14, 50, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, 78, C7, 4A, 00, E8, 41, 00, 00, 00, 83, C4, 14, 5D, C3, 55, 8B, EC, 8D, 45, 10, 50, 6A, 00, FF, 75, 0C, FF, 75, 08, 68, 5C, B6, 4A, 00, E8, 23, 00, 00, 00, 83, C4, 14, 5D, C3, 55, 8B, EC, 8D, 45, 10, 50, 6A, 00, FF, 75, 0C, FF, 75, 08, 68, 78, C7, 4A, 00, E8, 05, 00, 00, 00, 83...
 
[+]

Entropy:
7.1267

Code size:
815.5 KB (835,072 bytes)

The file pm.exe has been seen being distributed by the following 2 URLs.

Remove pm.exe - Powered by Reason Core Security