dlsecuretb_1.0.1.5.exe

DLSecure Toolbar

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application dlsecuretb_1.0.1.5.exe, “DLSecure Toolbar Installer” by Visicom Media has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. While running, it connects to the Internet address nat276.national-net.com on port 80 using the HTTP protocol.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
DLSecure Toolbar

Description:
DLSecure Toolbar Installer

Version:
1.0

MD5:
ab7a0a813215575d287c738ac8cc8a84

SHA-1:
e47f256b36a7f8be0607c6ccb0f60d223036c42e

SHA-256:
a7907bd225af117d16a15a7833d8e5ad9ad66f301f485dcae0c3371ea15ada59

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
The setup program may install a variant of the Visicom Toolbar, a web browser extension that may modify the browser's home and search pages.

Analysis date:
4/19/2024 2:59:55 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Visicom
7.1.1

Dr.Web
Adware.Toolbar.272
9.0.1.0330

ESET NOD32
Win32/Toolbar.Visicom (variant)
8.10784

Fortinet FortiGate
Riskware/Visicom
11/26/2014

Malwarebytes
PUP.Optional.DLSecure.A
v2014.11.26.01

McAfee
Artemis!AB7A0A813215
5600.6934

Reason Heuristics
PUP.DLSecureToolbarInstaller.VisicomMedia.P
14.11.26.13

Trend Micro House Call
Suspicious_GEN.F47V1125
7.2.330

File size:
4 MB (4,202,040 bytes)

Product version:
1.0.1.5

Copyright:
© Visicom Media Inc. (License)

Trademarks:
Visicom Media Inc., All Rights Reserved

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\dlsecuretb_1.0.1.5.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
5/8/2014 2:00:00 AM

Valid to:
6/21/2016 1:59:59 AM

Subject:
CN=Visicom Media Inc., OU=SECURE APPLICATION DEVELOPMENT, O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
266F9E30991B0C3EFC03DA9B8CDDB68D

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:cg6nAj3FWRYOca/CTXfvVwrB4zRPfFtS66QdIxgB8:cnUWRYeovtPfHSnQdIxV

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file dlsecuretb_1.0.1.5.exe has been seen being distributed by the following 9 URLs.

temp:dlsecureTb_1.0.1.5-1.exe

http://dlsecure.com/toolbar/dlsecure/.../DLSecureToolbar.exe

temp:dlsecureTb_1.0.1.5.exe

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to nat276.national-net.com  (66.115.160.33:80)

Remove dlsecuretb_1.0.1.5.exe - Powered by Reason Core Security