deals plugin-bg.exe

Deals Plugin

Awesome Apps

This is part of a distribution package that is classified as adware distributed by 50onRed. This adware is used to interact with the installed web browsers and inject ads and modify the default search and homepages. The application deals plugin-bg.exe by Awesome Apps has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
215 Apps  (signed by Awesome Apps)

Product:
Deals Plugin

Description:
Deals Plugin exe

Version:
1.1.151.34

MD5:
1d20ecb2ee4f36a2969b82c584c749ac

SHA-1:
03a213f8ac1075bed470f5f6e1f582282b8ed288

SHA-256:
ba46971dde70af6a6c9d8f5e33d82bc455cdea81bd58b592d269f50ec0189069

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/20/2024 2:02:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.50OnRed.AwesomeApps (M)
16.2.5.22

File size:
926.4 KB (948,608 bytes)

Product version:
1.1.151.34

Copyright:
Copyright 2011

Original file name:
Deals Plugin.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\deals plugin\deals plugin-bg.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/29/2012 9:00:00 AM

Valid to:
8/30/2013 8:59:59 AM

Subject:
CN=Awesome Apps, O=Awesome Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3D0C9CCF6A7D44B9FDA1963A424319BA

File PE Metadata
Compilation timestamp:
10/25/2012 10:21:18 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:V426LjFso+pSzEhAWz9w5z46TRkXZWa62kA:VYjUpSYhAHB4BXZWajkA

Entry address:
0x8A405

Entry point:
E8, F4, AC, 00, 00, E9, 89, FE, FF, FF, 2D, A4, 03, 00, 00, 74, 22, 83, E8, 04, 74, 17, 83, E8, 0D, 74, 0C, 48, 74, 03, 33, C0, C3, B8, 04, 04, 00, 00, C3, B8, 12, 04, 00, 00, C3, B8, 04, 08, 00, 00, C3, B8, 11, 04, 00, 00, C3, 8B, FF, 56, 57, 8B, F0, 68, 01, 01, 00, 00, 33, FF, 8D, 46, 1C, 57, 50, E8, AB, CD, FF, FF, 33, C0, 0F, B7, C8, 8B, C1, 89, 7E, 04, 89, 7E, 08, 89, 7E, 0C, C1, E1, 10, 0B, C1, 8D, 7E, 10, AB, AB, AB, B9, A8, 43, 4E, 00, 83, C4, 0C, 8D, 46, 1C, 2B, CE, BF, 01, 01, 00, 00, 8A, 14, 01...
 
[+]

Entropy:
6.5442

Code size:
775 KB (793,600 bytes)

Remove deals plugin-bg.exe - Powered by Reason Core Security