zune file is corrupt.exe

Daily ApPs FORfor

The application zune file is corrupt.exe by Daily ApPs FORfor has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from getm.0117g.info.
Publisher:
FHPIZ  (signed by Daily ApPs FORfor)

Product:
FHPIZ

Version:
5031.1562.1240.4997

MD5:
d0e71d30e60e023fd88d7aa65918f084

SHA-1:
3fe92befd0ccd08c4357736ae67a6dcd04033c05

SHA-256:
86857b6f733eacaf1a84cd7964fcc1d34ee2e675669b85d5a6def4eb9ccbf536

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/27/2024 3:58:23 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Downloader
2016.0.3089

Dr.Web
Trojan.OutBrowse.746
9.0.1.05190

ESET NOD32
Win32/OutBrowse.CB potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
6/3/2015

K7 AntiVirus
Unwanted-Program
13.204.16128

McAfee
Adware-OutBrowse.g
5600.6745

Quick Heal
PUA.OutBrowse.A
6.15.14.00

Reason Heuristics
PUP.Outbrowse.Installer
15.6.1.23

Trend Micro House Call
Suspici.2DBCF6CF
7.2.154

File size:
661.8 KB (677,632 bytes)

Product version:
5031.1562.1240.4997

Copyright:
FHPIZ

Trademarks:
FHPIZ

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Digital Signature
Authority:
thawte, Inc.

Valid from:
5/31/2015 3:00:00 AM

Valid to:
1/28/2016 1:59:59 AM

Subject:
CN=Daily ApPs FORfor, O=Daily ApPs FORfor, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
035E34E974BFABE275BE7932F1212443

File PE Metadata
Compilation timestamp:
12/6/2009 12:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:ABRlsphbiUukxQVDSNtVkV9/QtFYmngkMOoWW/fc8vy4hE:ABnahAkxQawmn1nWM86l

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file zune file is corrupt.exe has been seen being distributed by the following URL.

Remove zune file is corrupt.exe - Powered by Reason Core Security