discountdragon.exe

Discount Dragon

Engaging Apps

This is the installer application for a 50onRed advertising supported software package (displays ads in the browser and may hijack the home and search pages of the web browser). The application discountdragon.exe, “Discount Dragon Installer” by Engaging Apps has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Innovative Apps  (signed by Engaging Apps)

Product:
Discount Dragon

Description:
Discount Dragon Installer

Version:
1.29.153.2

MD5:
d803e40d1e94bae10f8692ab5dee824d

SHA-1:
71608996fa1977eccae2f8c8eb021e17c357dd04

SHA-256:
4036787d25f73f3c21884de0745ba19806f0a15ff10b0ede5223d450017bcb38

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
6/17/2019 4:12:19 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.ScrambleWrapper
7.1.1

Dr.Web
Trojan.Crossrider.10
9.0.1.0260

ESET NOD32
Win32/Packed.ScrambleWrapper
8.9820

K7 AntiVirus
Unwanted-Program
13.177.12128

Malwarebytes
PUP.Optional.DiscountDragon.A
v2014.09.17.12

McAfee
Artemis!D803E40D1E94
5600.7004

Reason Heuristics
PUP.Installer.EngagingApps.O
14.9.17.12

Sophos
AppRider
4.98

VIPRE Antivirus
GamePlayLabs
29382

XVirus List
Win32.Detected
2.9.17

File size:
3.8 MB (3,986,568 bytes)

Copyright:
Copyright Innovative Apps

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\discountdragon.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/3/2013 5:00:00 PM

Valid to:
6/4/2014 4:59:59 PM

Subject:
CN=Engaging Apps, O=Engaging Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
632EEBD9B987BC680D444D8675A26545

File PE Metadata
Compilation timestamp:
2/19/2012 7:01:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:z0l6Kij5dV3xCbzztvDIwz5ifo1fgrgfRQKoLjjv:S6KudNxAz59Fd1MCoz

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 93, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 94, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 94, 42, 00, 56, A3, 40, 7B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 7B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 94, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9932  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file discountdragon.exe has been seen being distributed by the following URL.

Remove discountdragon.exe - Powered by Reason Core Security