coupondropdown-bg.exe

CouponDropDown

Awesome Apps

This is part of a distribution package that is classified as adware distributed by 50onRed. This adware is used to interact with the installed web browsers and inject ads and modify the default search and homepages. The application coupondropdown-bg.exe, “CouponDropDown exe” by Awesome Apps has been detected as adware by 32 anti-malware scanners. Part of the Corssrider web browser platform, the BG executable is a background process that manage various function of the installed extensions in user's browser including managing installation, updates and remote code downloads.
Publisher:
215 Apps  (signed by Awesome Apps)

Product:
CouponDropDown

Description:
CouponDropDown exe

Version:
1.1.151.46

MD5:
8b19278af321b590f9560be8c1e84af6

SHA-1:
9b8057e7b6e3d52ee36371bf802b5f49fb1e2b56

SHA-256:
97f9f1d247b5ab2cb35eac1d1c7c9d75283d487b5ea73223ef0b6ceef25b467b

Scanner detections:
32 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application. The owner/publisher of this file is Awesome Apps.

Analysis date:
4/24/2024 11:06:04 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.NNP
366

Agnitum Outpost
PUA.Toolbar.CrossRider
7.1.1

AhnLab V3 Security
PUP/Win32.MulDrop
2014.02.15

Avira AntiVirus
ADWARE/CrossRider.Gen2
8.3.1.6

avast!
Win32:RadyoosMedia-A [PUP]
2014.9-160203

AVG
Crossrider
2017.0.2844

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.1623

Bitdefender
Adware.Agent.NNP
1.0.20.170

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Agent-2199
0.98/21511

Comodo Security
UnclassifiedMalware
22366

Dr.Web
Trojan.Crossrider1.26368
9.0.1.034

Emsisoft Anti-Malware
Adware.Agent.NNP
8.16.02.03.01

ESET NOD32
Win32/Toolbar.CrossRider.H potentially unwanted (variant)
10.11746

F-Prot
W32/Crossrider.B.gen
v6.4.7.1.166

F-Secure
Adware.Agent.NNP
11.2016-03-02_4

G Data
Adware.Agent.NNP
16.2.25

IKARUS anti.virus
AdWare.Agent
t3scan.1.9.5.0

K7 AntiVirus
Unwanted-Program
13.204.16151

Malwarebytes
PUP.CrossRider.CDD
v2016.02.03.01

McAfee
RDN/Generic PUP.z!fc
5600.6500

MicroWorld eScan
Adware.Agent.NNP
17.0.0.102

NANO AntiVirus
Trojan.Win32.Plugin.crbipj
0.30.24.1636

nProtect
Adware.Agent.NNP
15.06.05.01

Reason Heuristics
PUP.50OnRed.AwesomeApps (M)
16.2.3.13

Sophos
CouponDropDown
4.98

Trend Micro House Call
TROJ_GEN.R0C1C0OLU14
7.2.34

Trend Micro
TROJ_GEN.R0C1C0OLU14
10.465.03

Vba32 AntiVirus
Trojan.Agent
3.12.26.4

VIPRE Antivirus
GamePlayLabs
40904

ViRobot
Trojan.Win32.A.Agent.907648[h]
2014.3.20.0

Zillya! Antivirus
Backdoor.PePatch.Win32.41950
2.0.0.2210

File size:
926.4 KB (948,608 bytes)

Product version:
1.1.151.46

Copyright:
Copyright 2011

Original file name:
CouponDropDown.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\coupondropdown\coupondropdown-bg.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/28/2012 6:00:00 PM

Valid to:
8/29/2013 5:59:59 PM

Subject:
CN=Awesome Apps, O=Awesome Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3D0C9CCF6A7D44B9FDA1963A424319BA

File PE Metadata
Compilation timestamp:
10/17/2012 6:34:04 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:t700I1m5NvqJqtiIpvyFfcwV+GRzgVBZWIltpFWZQv7Meij8k8ijw9OuUVJB0FgS:U0IFjKHxS8ka6iNqz1rOZyjExYa20

Entry address:
0x8A2F5

Entry point:
E8, F4, AC, 00, 00, E9, 89, FE, FF, FF, 2D, A4, 03, 00, 00, 74, 22, 83, E8, 04, 74, 17, 83, E8, 0D, 74, 0C, 48, 74, 03, 33, C0, C3, B8, 04, 04, 00, 00, C3, B8, 12, 04, 00, 00, C3, B8, 04, 08, 00, 00, C3, B8, 11, 04, 00, 00, C3, 8B, FF, 56, 57, 8B, F0, 68, 01, 01, 00, 00, 33, FF, 8D, 46, 1C, 57, 50, E8, AB, CD, FF, FF, 33, C0, 0F, B7, C8, 8B, C1, 89, 7E, 04, 89, 7E, 08, 89, 7E, 0C, C1, E1, 10, 0B, C1, 8D, 7E, 10, AB, AB, AB, B9, A8, 43, 4E, 00, 83, C4, 0C, 8D, 46, 1C, 2B, CE, BF, 01, 01, 00, 00, 8A, 14, 01...
 
[+]

Entropy:
6.5477

Code size:
775 KB (793,600 bytes)

Remove coupondropdown-bg.exe - Powered by Reason Core Security