ts_10051.exe

TSearch

SISTEMA LTD

The application ts_10051.exe by SISTEMA has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from filesharingbox.com.
Publisher:
Company Inc.  (signed by SISTEMA LTD)

Product:
TSearch

Version:
1.0.0.51

MD5:
67cec2e9ff0cb00d1946e720ff05a38f

SHA-1:
b50764dc2dd7d4ea9547525e57d7acc867ed591a

SHA-256:
92468073d69b830bb6b8a8fa601db4829d0a1e4f5814305aeae8ca6dce8005a8

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
11/27/2024 1:09:05 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Neobar
7.1.1

AVG
Generic
2016.0.3072

ESET NOD32
Win32/Toolbar.Neobar.N potentially unwanted (variant)
9.11814

IKARUS anti.virus
not-a-virus:WebToolbar.Agent
t3scan.1.9.5.0

Malwarebytes
PUP.Optional.NeoBar.A
v2015.06.20.12

NANO AntiVirus
Riskware.Win32.Downware.dskslt
0.30.24.2086

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.SISTEMA.Installer (M)
15.6.20.8

Trend Micro House Call
Suspici.A3751E06
7.2.171

VIPRE Antivirus
Trojan.Win32.Generic
41282

File size:
2.2 MB (2,336,056 bytes)

Product version:
1.0.0.51

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ts_10051.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
3/27/2015 1:00:00 AM

Valid to:
3/27/2016 12:59:59 AM

Subject:
CN="""SISTEMA LTD""", O="""SISTEMA LTD""", L=Cherepovec, S=Cherepovec, C=RU

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
45C715A0E1CDBE0A8338DF4C176F254D

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:sLS9VWRWfStfvXHWZI9y4GcvqgqlVBTej9YNKpivRbqtCD6vhzxP74kE:seVWpnZ9y4rvqgqH4hY4ipetCezxP74H

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file ts_10051.exe has been seen being distributed by the following URL.

Remove ts_10051.exe - Powered by Reason Core Security