gimpsetup.exe

KBM2 Installer

Best Download Manager

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application gimpsetup.exe by Best Download Manager has been detected as adware by 7 anti-malware scanners. The file has been seen being downloaded from api.kbm2.com. While running, it connects to the Internet address api.yontoo.com on port 80 using the HTTP protocol.
Publisher:
Best Download Manager   (signed by Best Download Manager)

Product:
KBM2 Installer

Version:
2.5.1.0

MD5:
9c41eb22a576ddeceac35e676e0c1a9d

SHA-1:
e47daa1c62173234136b0f219ad4eaa0522a938c

SHA-256:
8a37c46634cede8f5877ffe08ec3a8662455897965223791bb7e0aa2dee456a1

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Belongs to the Sambreel/Yontoo progam that inserts various forms of advertising in the user's web browser, installed with minimal or no user consent.

Analysis date:
4/19/2024 11:54:36 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
AdInject.Bdmngr
2015.0.3570

Dr.Web
Adware.Plugin.85
9.0.1.038

ESET NOD32
Win32/KBM (variant)
8.9159

McAfee
Artemis!9C41EB22A576
5600.7226

Reason Heuristics
PUP.Installer.BestDownloadManager.J
14.8.8.0

Trend Micro House Call
TROJ_GEN.F47V1116
7.2.38

VIPRE Antivirus
sterkly LLC
24244

File size:
650.1 KB (665,736 bytes)

Product version:
2.5.1.0

Copyright:
(c) Best Download Manager . All rights reserved.

Original file name:
KBM2.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\gimpsetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/24/2013 5:00:00 PM

Valid to:
7/25/2015 4:59:59 PM

Subject:
CN=Best Download Manager, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Best Download Manager, L=Carlsbad, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5F3BBF9CAABCE7C81AB69ABF7371A064

File PE Metadata
Compilation timestamp:
8/7/2013 12:25:15 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:1gq6uX5c0RzWguzZylIAllGVytvHdKme7IZopY1Q/+ge3BLQ/Q:1R610ZluglqytYmesZoX+jZQo

Entry address:
0x3A3C0

Entry point:
E8, 0E, 6F, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, D0, 0B, 47, 00, 75, 02, F3, C3, E9, 95, 6F, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 85, F6, 75, 04, 33, C0, EB, 61, 83, 7D, 08, 00, 75, 13, E8, D9, 35, 00, 00, 6A, 16, 5E, 89, 30, E8, 6C, 75, 00, 00, 8B, C6, EB, 48, 83, 7D, 10, 00, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 66, 70, 00, 00, 83, C4, 0C, EB, C7, FF, 75, 0C, 6A, 00, FF, 75, 08, E8, B4, 31, 00, 00, 83, C4, 0C, 83, 7D, 10, 00, 74, BB, 39, 75, 0C, 73, 0E, E8, 8F, 35, 00, 00, 6A...
 
[+]

Entropy:
6.2684

Code size:
342.5 KB (350,720 bytes)

The file gimpsetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to wac.edgecastcdn.net  (72.21.81.13:80)

TCP (HTTP):
Connects to service.yontoo.com  (8.25.35.148:80)

TCP (HTTP):
Connects to api.yontoo.com  (8.25.35.15:80)

Remove gimpsetup.exe - Powered by Reason Core Security