1_offer_7.exe

Outfox Tv Productions Pty Ltd

The application 1_offer_7.exe by Outfox Tv Productions Pty has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn.download4desktop.com.
Publisher:
Outfox Tv Productions Pty Ltd  (signed and verified)

MD5:
4dcb6f1037a40ebb5679c75eb509772a

SHA-1:
5d4e2952b3aeb35c35c303287d5c950d663164b1

SHA-256:
21ffade55a8aabf54f90a466844081206f00ffe3795827817f91e15aab55b628

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 6:11:51 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Toolbar.224
9.0.1.0135

Reason Heuristics
PUP.OutfoxTvProductionsPty.J
14.5.15.22

File size:
704.9 KB (721,848 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\1_offer_7.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/2/2013 7:00:00 PM

Valid to:
12/3/2014 6:59:59 PM

Subject:
CN=Outfox Tv Productions Pty Ltd, O=Outfox Tv Productions Pty Ltd, STREET=129 Robertson Street, L=Fortitude Valley, S=Qld, PostalCode=4006, C=AU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0DB9E809D891B3D1DE926581A15676EA

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:LJgNNNM+lom6j85hyaF/NmX9SMxnss1IyYZY2cdGHIckljhV+NJQg08WBSoJ+:LJ8g+OmS8TmXxsIIZZY2IGoxjhGJb0tM

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9211

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file 1_offer_7.exe has been seen being distributed by the following URL.

Remove 1_offer_7.exe - Powered by Reason Core Security