zendealsapp9c0.exe

Zendeals

The application zendealsapp9c0.exe by Zendeals has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from d1uc4fr8hoy8ts.cloudfront.net.
Publisher:
Zendeals  (signed and verified)

MD5:
d3a784d0dce50d1fc4d4501881e3fbe8

SHA-1:
58b9d34a93ece325853efa0bee39f38d94dfe712

SHA-256:
ac6e234d4a19a231f1c8c78e79f44ce2da040d1195ea0b085920ddc386341a84

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 1:48:46 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Zendeals.Installer (M)
15.11.6.13

Trend Micro House Call
TROJ_GEN.F47V0124
7.2.310

File size:
303.2 KB (310,504 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\zendealsapp9c0.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/24/2012 8:00:00 PM

Valid to:
6/25/2013 7:59:59 PM

Subject:
CN=Zendeals, O=Zendeals, STREET=2051 EL CAMINO REAL STE 201, L=Palo Alto, S=CA, PostalCode=94306, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009568359009204743CC41A46F1F647B63

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:4QqQuVHO5KeTn9j5aVjQiVV4MT3nEtTvlKaVDXahGZJYlf6:olO5LTn9j5a5QivnT3nEOyr6lf6

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8596

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file zendealsapp9c0.exe has been seen being distributed by the following URL.

Remove zendealsapp9c0.exe - Powered by Reason Core Security