hqwltkainwuvu.exe

DiscountyFrenz1.2

PlusDiscount-FrenzComp

The application hqwltkainwuvu.exe, “DiscountyFrenz1.2 Installer” has been detected as adware by 24 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address hwcdn.net on port 80 using the HTTP protocol.
Publisher:
PlusDiscount-FrenzComp

Product:
DiscountyFrenz1.2

Description:
DiscountyFrenz1.2 Installer

Version:
1.36.01.22

MD5:
5a15a74ffd990be0e45062bd50d75460

SHA-1:
3f097d921d1efb4ddda8382f664510ba51777ac2

SHA-256:
c08cab06de4a438aacd6ae3094191452d8622a253951d4a8117773a571e02e4d

Scanner detections:
24 / 68

Status:
Adware

Explanation:
This is part of the Crossrider Internet browser extension framework which may modify the user's web browser settings including changing the home and search pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/26/2024 4:39:53 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.JS.Agent.AM
5654257

Agnitum Outpost
PUA.Toolbar.CrossRider
7.1.1

AhnLab V3 Security
PUP/Win32.CrossRider
2015.06.04

Avira AntiVirus
ADWARE/CrossRider.Gen7
8.3.1.6

avast!
Dropper-gen [Drp]
150602-1

AVG
Potentially harmful program Crossrider.PSK
2014.0.4311

Dr.Web
infected with Trojan.Crossrider.46916
9.0.1.05190

ESET NOD32
Win32/Toolbar.CrossRider.CM potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/CrossRider
6/4/2015

G Data
Script.Application.Plush
15.6.25

K7 AntiVirus
Adware
13.204.16134

Kaspersky
not-a-virus:AdWare.Win32.Agent
15.0.0.543

Malwarebytes
PUP.Optional.DiscountFrenzy.A
v2015.06.04.08

McAfee
Trojan.Artemis!E28F16F65A8A
18.0.204.0

MicroWorld eScan
Gen:Application.Parj.1
16.0.0.465

NANO AntiVirus
Riskware.Win32.CrossRider.dskphk
0.30.24.1636

Panda Antivirus
Trj/Genetic.gen
15.06.04.08

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Downloader.Installer
15.6.4.3

Trend Micro House Call
Suspici.9DDE4AEF
7.2.155

Trend Micro
ADW_CROSSRIDER
10.465.04

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

VIPRE Antivirus
Threat.4150696
40786

Zillya! Antivirus
Trojan.BlackGen.Win32.11
2.0.0.2205

File size:
9.4 MB (9,888,359 bytes)

Copyright:
Copyright PlusDiscount-FrenzComp

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\hqwltkainwuvu.exe

File PE Metadata
Compilation timestamp:
12/4/2012 4:55:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
196608:snfwkya/eIVpjmivsYDpSyb2qTwrEO0EgW/CzWx1M1sI:kPneI/Kiv2yaccEZo/So17I

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9984  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to s3-website-us-east-1.amazonaws.com  (54.231.2.44:80)

TCP (HTTP):
Connects to hwcdn.net  (69.16.175.42:80)

TCP (HTTP):
Connects to ec2-23-21-247-21.compute-1.amazonaws.com  (23.21.247.21:80)

Remove hqwltkainwuvu.exe - Powered by Reason Core Security