coupon server.exe

App Squad

This is the installer application for a 50onRed advertising supported software package (displays ads in the browser and may hijack the home and search pages of the web browser). The application coupon server.exe by App Squad has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer. It is also typically executed from the user's temporary directory.
Publisher:
App Squad  (signed and verified)

MD5:
6b78f0b7cb83aeffae3525ce3ea61ffb

SHA-1:
cae4f295fa1cdb3e9c97820b0e155bfe425d18a1

SHA-256:
788523f2db1e9d32171d68139b1fbf8471ce67a7a46fa23d7dedb68d235ef0a4

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/3/2024 8:36:38 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.50OnRed.AppSquad.Installer (M)
16.1.19.10

File size:
1.3 MB (1,404,200 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\software\coupon server.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/18/2014 12:00:00 AM

Valid to:
3/25/2015 11:59:59 PM

Subject:
CN=App Squad, O=App Squad, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
49F47D57212B012C506E1CB5CE9AF0F8

File PE Metadata
Compilation timestamp:
2/19/2012 3:01:49 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
24576:CtBj1vmBoO+hkdZ3aVe7AFow6/cywcUdYv9nFNhD2:C7PCsekyBRUdunFzD2

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 93, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 94, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 94, 42, 00, 56, A3, 40, 7B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 7B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 94, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9656  (probably packed)

Code size:
34.5 KB (35,328 bytes)

Remove coupon server.exe - Powered by Reason Core Security