20365.exe

Smart Apps

This is the installer application for a 50onRed advertising supported software package (displays ads in the browser and may hijack the home and search pages of the web browser). The application 20365.exe by Smart Apps has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.updatesrv.com.
Publisher:
Smart Apps  (signed and verified)

MD5:
30c5d9a632136129ca470a0efa3d645b

SHA-1:
d1daed458a62dd0e9cd3aaf63403107ef9574098

SHA-256:
0890ac7c97717ac47d25f56ef70190939f309cca7d6edddf168a6b066e236bd0

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/4/2024 2:12:05 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.50OnRed.SmartApps.Installer (M)
15.12.31.9

File size:
479 KB (490,472 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Common path:
C:\users\{user}\appdata\local\temp\20365.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/24/2013 7:00:00 PM

Valid to:
3/25/2014 6:59:59 PM

Subject:
CN=Smart Apps, O=Smart Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7CAFCF7841E5BDDF79F61691D678D0EC

File PE Metadata
Compilation timestamp:
2/19/2012 9:01:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
12288:8tobaKnJFWDHSrCMY6x52TsPx3T3WHdevgvhxIQt:8tJKnLWDSuMXPx3T3W4ovhxV

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 93, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 94, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 94, 42, 00, 56, A3, 40, 7B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 7B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 94, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.8382  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file 20365.exe has been seen being distributed by the following URL.

Remove 20365.exe - Powered by Reason Core Security