topsadon1c.exe

neomedia

The application topsadon1c.exe by neomedia has been detected as a potentially unwanted program by 3 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘topsadonc’. The file has been seen being downloaded from down1.topsadon1.com.
Publisher:
neomedia  (signed and verified)

MD5:
fec2b2fa68cd4b48fe59bd0ddd94b529

SHA-1:
0aca7a17afe7954041c98bfac1593e3b2b97a53d

SHA-256:
221dcafe3ec335d55a5e1aca83a6f2f613261a0e7a7d7a4bb055ec0e13e65045

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 11:47:02 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/AdWare.KeywordFind.D application
8.0.319.0

F-Prot
W32/Themida_Packed
4.6.5.141

VIPRE Antivirus
Threat.4412848
48690

File size:
997.7 KB (1,021,672 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\topsadon1c.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
1/25/2016 9:00:00 AM

Valid to:
1/25/2017 8:59:59 AM

Subject:
CN=neomedia, OU=IT Team, O=neomedia, L=Gangnam-gu, S=SEOUL, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
343766F67EC25EF07DB4A9C47879EAF6

File PE Metadata
Compilation timestamp:
4/25/2016 3:55:50 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:0f2vJYlNX/zUX2vEU5Plu91gc4emG8mqBY8zUGHiP7:0f2v0pzUX2vZ5PlwyQ8mqeGiz

Entry address:
0x22D000

Entry point:
83, EC, 04, 50, 53, E8, 01, 00, 00, 00, CC, 58, 8B, D8, 40, 2D, 00, D0, 0B, 00, 2D, 5D, 36, 5F, 00, 05, 52, 36, 5F, 00, 80, 3B, CC, 75, 19, C6, 03, 00, BB, 00, 10, 00, 00, 68, 69, 3A, ED, 10, 68, 9E, 83, A4, 4D, 53, 50, E8, 0A, 00, 00, 00, 83, C0, 00, 89, 44, 24, 08, 5B, 58, C3, 55, 8B, EC, 60, 8B, 75, 08, 8B, 4D, 0C, C1, E9, 02, 8B, 45, 10, 8B, 5D, 14, EB, 08, 31, 06, 01, 1E, 83, C6, 04, 49, 0B, C9, 75, F4, 61, C9, C2, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5853

Code size:
418.5 KB (428,544 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
topsadonc

Command:
"C:\users\{user}\appdata\roaming\topsadon\topsadon1c.exe"


The file topsadon1c.exe has been seen being distributed by the following URL.

Remove topsadon1c.exe - Powered by Reason Core Security