radarsync.exe

RadarSync

The application radarsync.exe by RadarSync has been detected as a potentially unwanted program by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from www.radarsync.com.
Publisher:
RadarSync  (signed and verified)

MD5:
659b05c2c8c400dea8100533631182de

SHA-1:
049a1f33e45d5d8e09bb26451d29fb4ea82319a7

SHA-256:
09f0c2963442e4c3ccfd53c94c5b997c8b82d9ac88a01cc8d263c5d38d5f949d

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
11/27/2024 5:37:04 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Trojan.Win32.InstallMonetizer
4.0.3.14111

Boost by Reason
Optional.RadarSync.J
188163

Dr.Web
Adware.Searcher.2593
9.0.1.0361

ESET NOD32
Win32/InstallMonetizer.AG
8.9255

McAfee
Artemis!659B05C2C8C4
5600.7268

NANO AntiVirus
Trojan.Win32.Searcher.cjaztx
0.28.0.57029

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.131225

Trend Micro House Call
TROJ_GEN.F47V0825
7.2.361

VIPRE Antivirus
Wajam
25130

File size:
444.4 KB (455,016 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\radarsync.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/3/2013 1:00:00 AM

Valid to:
1/4/2014 12:59:59 AM

Subject:
CN=RadarSync, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=RadarSync, L=Highland Park, S=Illinois, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6B438BAA69E79D0557305C3D2DAC697E

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:EHWT7pYMCBSVHRCjkaD/p87bJd588AyaVbJd5A8L:EHMZCWgjka67bJd588AyaVbJd5A8L

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file radarsync.exe has been seen being distributed by the following URL.

Remove radarsync.exe - Powered by Reason Core Security