audacityinstaller.exe

Nextup

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application audacityinstaller.exe by Nextup has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. The file has been seen being downloaded from inst.amazing-sw.com.
Publisher:
Nextup  (signed and verified)

Version:
1.0.1.176

MD5:
323f47a4638e3aaf3f332cfb63cfa8e0

SHA-1:
52a0dbd404b81cd64ffd8c91907a60a1c5f75572

SHA-256:
6a767b051ddd2215319a04ecbf22f0ed356d3c23074de534e4e48a747eede0c4

Scanner detections:
17 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/15/2025 5:48:24 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen7
7.11.207.78

avast!
Malware-gen
150129-1

AVG
Generic
2016.0.3208

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.Verti.JBT
20967

ESET NOD32
Win32/Verti.J potentially unwanted application
7.0.302.0

G Data
Win32.Application.Nextup
15.2.25

IKARUS anti.virus
PUA.Verti
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.193.14867

Kaspersky
not-a-virus:AdWare.Win32.Verti
15.0.0.543

Malwarebytes
PUP.Optional.Nextup
v2015.02.05.01

NANO AntiVirus
Riskware.Win32.Verti.dmncmr
0.30.0.65070

Norman
Agent.BKBXY
11.20150205

Panda Antivirus
Generic Suspicious
15.02.05.01

Reason Heuristics
PUP.Nextup
15.2.5.1

Sophos
PUA 'NextUp'
5.10

VIPRE Antivirus
Threat.4786530
37240

File size:
364.2 KB (372,936 bytes)

Product version:
1.0.1.176

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\downloads\audacityinstaller.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/21/2014 5:00:00 PM

Valid to:
5/22/2015 4:59:59 PM

Subject:
CN=Nextup, O=Nextup, STREET=10900 NE 8TH ST, STREET=STE 1000, L=Bellevue, S=WA, PostalCode=98004, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C705E6F899AC0C37A4458683DB2745BB

File PE Metadata
Compilation timestamp:
1/29/2015 1:22:12 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:iXzh6JQNiFHJRwBh6M/XfEKVtbdYUa97IyW87BkzfqHurcyTxqKE4A/U20q:8V6KNUwBh6QvXtyUa9MyWVeOa/U20q

Entry address:
0x16D5C0

Entry point:
60, BE, 00, B0, 51, 00, 8D, BE, 00, 60, EE, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8425

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
332 KB (339,968 bytes)

The file audacityinstaller.exe has been seen being distributed by the following URL.

Remove audacityinstaller.exe - Powered by Reason Core Security