انشودة لا تقولوا لقد فقدنا الشهيدا للشيخ سعد الغامدي.exe

GreenApp

This uses the software InstalleRex download manager which bundles a number of adware plugin and browser extensions and is distributed via TusFiles. The application انشودة لا تقولوا لقد فقدنا الشهيدا للشيخ سعد الغامدي.exe, “Installer for GreenApp” has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Tarma Installer installer, however the file is not signed with an authenticode signature from a trusted source.
Publisher:
GreenApp

Product:
GreenApp

Description:
Installer for GreenApp

Version:
2014.3.30.1503

MD5:
5667a044a1a737ad3608ef5f399fcdfb

SHA-1:
8201eba7690ae7f41df821f3a84444c68abe67a0

SHA-256:
6aa86e6e535ded11eaf6cba3ae94bdfb6bb7d50322f6e258aba8116458ae48ec

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses Web-Pick's 'File Product', an Installer which wraps various products and downloads and installs it silently through the process, hosted on TusFiles.

Analysis date:
4/19/2024 1:04:49 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware (M)
16.7.26.8

File size:
260.2 KB (266,417 bytes)

Product version:
1.0.0.3

Copyright:
Copyright © 2014 GreenApp

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
Tarma Installer

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\انشودة لا تقولوا لقد فقدنا الشهيدا للشيخ سعد الغامدي.exe

File PE Metadata
Compilation timestamp:
3/12/2013 9:51:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:yr/bUzkuvcBYC47l2xij4YTfpczmap8spMPed0Vz:yr0kuveY3cY1cia66MGd0Vz

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file انشودة لا تقولوا لقد فقدنا الشهيدا للشيخ سعد الغامدي.exe has been seen being distributed by the following URL.