adkn-adknowledge-sntb.exe

Adknowledge

Zugo Ltd

The application adkn-adknowledge-sntb.exe by Zugo has been detected as adware by 5 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn.install.oibundles.com.
Publisher:
Zugo Ltd  (signed and verified)

Product:
Adknowledge

Version:
1.0

MD5:
1bc331eb14a24d70879d3166c311569c

SHA-1:
11848c655093cb160e5fff4db23be0d0d23bb855

SHA-256:
8630fcd0a957ce2966c122f8ac40ba882e262cf60601889d71c53e4af054c5ce

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
4/16/2024 8:32:12 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Zugo.71
9.0.1.0225

ESET NOD32
Win32/Toolbar.Zugo
9.8894

Fortinet FortiGate
Adware/Zugo
8/13/2015

Malwarebytes
PUP.Optional.SweetPacks.A
v2015.08.13.09

Reason Heuristics
PUP.Zugo.Installer (M)
15.8.13.9

File size:
720.6 KB (737,936 bytes)

Product version:
1.0

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\adkn-adknowledge-sntb.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
1/27/2011 4:00:00 PM

Valid to:
1/27/2013 3:59:59 PM

Subject:
CN=Zugo Ltd, O=Zugo Ltd, STREET=PO Box 36, STREET=1st Floor, STREET=37 Broad St., L=St Helier, S=Jersey, PostalCode=JE4 9NU, C=JE

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
46241CDE5C7B500B51C5F1328228F2A9

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:LJDr2hwgEl+H/oDyb3cvI2yBzMDXdtO2juzlrCAX3h:LJ2FJ/oD4FWBtfjuzAAh

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9443

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file adkn-adknowledge-sntb.exe has been seen being distributed by the following URL.

Remove adkn-adknowledge-sntb.exe - Powered by Reason Core Security