air2f44.exe

Id-Btxkgwokxatk

Clash Project (Bright Circle Investments Ltd)

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application air2f44.exe by Clash Project (Bright Circle Investments) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn77.airdwnlds.com. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Zqlzolowry & co.  (signed by Clash Project (Bright Circle Investments Ltd))

Product:
Id-Btxkgwokxatk

Description:
Jzmvyfx

Version:
25.22.19.9

MD5:
6e259fb70161e0b5f1abedd0db55f1f7

SHA-1:
9602952dd1e60aebf18db90f79b36190c05f1da5

SHA-256:
e06cef359cfb53254c4ce12c1dab9f5dcf9c53e2872348b754e296d2f1b1670c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/2/2024 8:09:25 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.BrightCircle.ClashProjectBrightCircleInvestments
15.2.24.23

File size:
12.4 MB (13,039,416 bytes)

Copyright:
Copyright Byiddrmhjrhdj

Trademarks:
Btxkgwokxatk is a trademark of Nrajctrswd

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\air2f44.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/15/2014 10:00:00 PM

Valid to:
12/16/2015 9:59:59 PM

Subject:
CN=Clash Project (Bright Circle Investments Ltd), O=Clash Project (Bright Circle Investments Ltd), STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
75DD4745F68AF8221A12839F4A4F8FE1

File PE Metadata
Compilation timestamp:
12/4/2012 11:55:11 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
393216:Oop/+TqK2iLWK/zFnFKPZcI+4noq0sEhRIf/dBduZ8p/:8WK/zmZN+4nRcPYjdu6/

Entry address:
0x412D

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 73, 45, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 74, 45, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 74, 45, 00, 56, A3, F4, E7, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8B, 3B, 00, 00, A3, 50, E8, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A9, B2, 40, 00, FF, 15, AC, 74, 45, 00, 83, EC, 14, C7, 44, 24, 04, AA, B2, 40, 00, C7...
 
[+]

Code size:
33.5 KB (34,304 bytes)

The file air2f44.exe has been seen being distributed by the following URL.

Remove air2f44.exe - Powered by Reason Core Security