too.exe

Couponarific

This is the instaler for an an Adpeak program that shows ads in the browser without providing information about the ad's origin. Ads are injected as banners or text-links in random web pages. The application too.exe by Couponarific has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from d2baov6ticicd8.cloudfront.net.
Publisher:
Couponarific  (signed and verified)

MD5:
863df4966112346f98a0e2e8c58789d7

SHA-1:
13801c974e680b92ea8224c32080713338e4d202

SHA-256:
4fd430071aa24a2b201d35c7bcde3bc3a6522bd540d20ac2ff07a0eddfac3446

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Injects advertisements in the web browser in the form or banner ads and popups.

Analysis date:
12/26/2024 1:00:07 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Adware-gen [Adw]
141119-1

Dr.Web
infected with Trojan.DownLoad3.35130
9.0.1.05190

ESET NOD32
Win32/Adware.Adpeak.Q application
7.0.302.0

Fortinet FortiGate
Riskware/Adpeak
11/29/2014

McAfee
Artemis!1B7BD5754EA8
5600.6932

NANO AntiVirus
Trojan.Win32.DownLoad3.djkwer
0.28.6.63726

Reason Heuristics
PUP.Couponarific.D
14.12.10.9

Trend Micro House Call
Suspici.42AC0CB3
7.2.333

File size:
346.1 KB (354,360 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\too.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
10/6/2014 9:12:43 PM

Valid to:
10/7/2015 9:12:43 PM

Subject:
E=support@couponarific.com, CN=Couponarific, O=Couponarific, L=Seattle, S=WA, C=US

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D5217FDB68336D578AC0747743835652

File PE Metadata
Compilation timestamp:
10/7/2014 5:40:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:HoGzI1X2v2oN0W/DJ+rm1rVeSr1JfkCBwbXeuWfQr4A9d1Uv:Hbnvr/9Qa4Sr1qCabXeuWfQrXz1Uv

Entry address:
0x31FF

Entry point:
81, EC, D8, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 34, 71, 40, 00, 55, FF, 15, AC, 72, 40, 00, 6A, 09, A3, 78, 92, 42, 00, E8, FD, 2E, 00, 00, A3, C4, 91, 42, 00, 55, 8D, 44, 24, 38, 68, B4, 02, 00, 00, 50, 55, 68, 70, 06, 42, 00, FF, 15, 7C, 71, 40, 00, 68, C0, 92, 40, 00, 68, C0, 81, 42, 00, E8, 68, 2B, 00, 00, FF, 15, 38, 71, 40, 00, BB, 00, 40, 43, 00, 50, 53, E8, 56, 2B, 00, 00...
 
[+]

Entropy:
7.9494

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file too.exe has been seen being distributed by the following URL.

Remove too.exe - Powered by Reason Core Security