kerio-winroute-firewall-windows-downloader_en.exe

Ontecnia Media Networks, S.L.

The application kerio-winroute-firewall-windows-downloader_en.exe by Ontecnia Media Networks, S.L has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from mathematica.en.malavida.com and multiple other hosts.
Publisher:
Ontecnia Media Networks, S.L.  (signed and verified)

MD5:
01e1bd3cbd7f232a754ec25365900365

SHA-1:
516616229b1c918155f62e5174bf129d7d08f44b

Scanner detections:
7 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Analysis date:
4/18/2024 6:59:11 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Toolbar.Babylon
2015.0.3505

ESET NOD32
Win32/Malavida
8.9670

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.04.13.12

McAfee
Artemis!01E1BD3CBD7F
5600.7161

Reason Heuristics
PUP.OntecniaMediaNetworksSL.n
14.5.10.11

Trend Micro House Call
TROJ_GEN.F47V0411
7.2.103

VIPRE Antivirus
Malavida
28196

File size:
370.5 KB (379,416 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\kerio-winroute-firewall-windows-downloader_en.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/24/2014 2:00:00 AM

Valid to:
2/25/2015 1:59:59 AM

Subject:
CN="Ontecnia Media Networks, S.L.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Ontecnia Media Networks, S.L.", L=Valencia, S=Valencia, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
13BBD08E760487FF928FBC6CD276E85E

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:pQqnCXmnA0BjtmMzv4WpNqAXJ2WpMed+va8JjXZDqebkPBE1MqSqHYZowAIdZ:fC2NpnzlN9Xya4DqluaqSpYIdZ

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file kerio-winroute-firewall-windows-downloader_en.exe has been seen being distributed by the following 2 URLs.

http://mathematica.en.malavida.com/.../freedownloader