air8d1c.exe

Id-Nhcjo

Armageddon Labs (BrightCircle Investments Limited)

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application air8d1c.exe by Armageddon Labs (BrightCircle Investments Limited) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn77.airdwnlds.com. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Engpwsdpwm & co.  (signed by Armageddon Labs (BrightCircle Investments Limited))

Product:
Id-Nhcjo

Description:
Gbakcpzmlt

Version:
16.11.1.8

MD5:
d0c473d7675b6669eca41792989ee72e

SHA-1:
5b5675f0ac92e16cb6d633a90b1b0d317a897151

SHA-256:
bafe16bb95a2bbda15d10bd98230f8e71ef0cc8e57b6c66d076de1a79ab546b3

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/2/2024 9:19:05 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.BrightCircle.Engpwsdpwmco.Installer (M)
16.1.11.13

File size:
11.5 MB (12,104,064 bytes)

Copyright:
Copyright Amygtiatnt

Trademarks:
Nhcjo is a trademark of Xucjlgacbj

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\air8d1c.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/30/2014 10:00:00 PM

Valid to:
12/1/2015 9:59:59 PM

Subject:
CN=Armageddon Labs (BrightCircle Investments Limited), O=Armageddon Labs (BrightCircle Investments Limited), STREET=Athinodorou 3, STREET=Dasoupoli Strovolos, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C5692390E715129E144F950D09DA6E8A

File PE Metadata
Compilation timestamp:
12/4/2012 11:55:11 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
196608:/47peaNXN17emVfmeF9lwuJxWcZCrjqE8TVkAPbXNrmXSHGwDzpH55kcb:/YpeYXj7emVf7F/LJUcZMf8umN3mKz53

Entry address:
0x412D

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 73, 45, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 74, 45, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 74, 45, 00, 56, A3, F4, E7, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8B, 3B, 00, 00, A3, 50, E8, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A9, B2, 40, 00, FF, 15, AC, 74, 45, 00, 83, EC, 14, C7, 44, 24, 04, AA, B2, 40, 00, C7...
 
[+]

Code size:
33.5 KB (34,304 bytes)

The file air8d1c.exe has been seen being distributed by the following URL.

Remove air8d1c.exe - Powered by Reason Core Security