intertherm_electric_furnace_heating_relay_wiring_diagram.pdf_downloader.exe

Escolade Solutions LTD.

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application intertherm_electric_furnace_heating_relay_wiring_diagram.pdf_downloader.exe by Escolade Solutions has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.freefilesdownloader.com. It is distributed as part of the Brightcircle group of browser-extensions.
Publisher:
Escolade Solutions LTD.  (signed and verified)

Description:
iPumper

Version:
1.0.0.2

MD5:
8b904008c119675f38f087e07e0370ab

SHA-1:
757d1d97444bde4f556c2113d3a0f0cb8ffe0126

SHA-256:
e1517b8887ecda738dcc3e39bb13d32a3ca6a037a958b6bfa3de53de98a7fcb7

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/19/2024 4:04:25 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Brightcircle.Escolade (M)
16.7.3.10

File size:
4.6 MB (4,869,064 bytes)

Product version:
0.0.0.0

Original file name:
xyzBNbNT3.lnk_p

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\intertherm_electric_furnace_heating_relay_wiring_diagram.pdf_downloader.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/24/2012 7:00:00 PM

Valid to:
9/25/2013 6:59:59 PM

Subject:
CN=Escolade Solutions LTD., O=Escolade Solutions LTD., STREET=Akademica Vernadskogo blvd. 36-507, L=Kiev, S=Kiev, PostalCode=03451, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0FB283CB6EEA8D0204BFA51C4BCE925C

File PE Metadata
Compilation timestamp:
8/14/2013 7:57:08 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:oFVB4uYGgnkRLUDpHPCnFVAl1Fnf/nmOMP6n95jUfConGWD1/9I:oB4uYGgnlHPCFVAl1Fnf/mcofJntD1/m

Entry address:
0x42322

Entry point:
E8, D2, 9D, 00, 00, E9, 89, FE, FF, FF, 57, 8B, C6, 83, E0, 0F, 85, C0, 0F, 85, C1, 00, 00, 00, 8B, D1, 83, E1, 7F, C1, EA, 07, 74, 65, EB, 06, 8D, 9B, 00, 00, 00, 00, 66, 0F, 6F, 06, 66, 0F, 6F, 4E, 10, 66, 0F, 6F, 56, 20, 66, 0F, 6F, 5E, 30, 66, 0F, 7F, 07, 66, 0F, 7F, 4F, 10, 66, 0F, 7F, 57, 20, 66, 0F, 7F, 5F, 30, 66, 0F, 6F, 66, 40, 66, 0F, 6F, 6E, 50, 66, 0F, 6F, 76, 60, 66, 0F, 6F, 7E, 70, 66, 0F, 7F, 67, 40, 66, 0F, 7F, 6F, 50, 66, 0F, 7F, 77, 60, 66, 0F, 7F, 7F, 70, 8D, B6, 80, 00, 00, 00, 8D, BF...
 
[+]

Entropy:
4.6425

Code size:
395.5 KB (404,992 bytes)

The file intertherm_electric_furnace_heating_relay_wiring_diagram.pdf_downloader.exe has been seen being distributed by the following URL.