mein-gutscheincode.exe

Qfocnxtkzcizpc

Mein Gutscheincode GmbH

The application mein-gutscheincode.exe by Mein Gutscheincode GmbH has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from static.crossrider.com.
Publisher:
Cpizyf  (signed by Mein Gutscheincode GmbH)

Product:
Qfocnxtkzcizpc

Description:
Iblvtmxtxdlfi

Version:
1.1.1.1

MD5:
83df2698f66922b2c9820568ab34b1a4

SHA-1:
b06ae99858a1510f69f1afe7de8827e6513695c2

SHA-256:
086a930a26c02fd29baaa873b7c764b15201980aeb7c011da5e3632c0255e6f5

Scanner detections:
1 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/19/2024 2:52:47 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Crossrider.MeinGuts.Installer (M)
16.6.24.7

File size:
3.1 MB (3,224,352 bytes)

Copyright:
Ibnfg

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\mein-gutscheincode.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/25/2013 1:00:00 AM

Valid to:
3/26/2015 12:59:59 AM

Subject:
CN=Mein Gutscheincode GmbH, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mein Gutscheincode GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6DC967C1E9C4DBE86E88DB14D51147D4

File PE Metadata
Compilation timestamp:
1/5/2010 1:09:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
98304:oe+beUTINpEf6RK/S6kXxQsrEU1oc/hAS:GhepM6R2kX2srtOc/uS

Entry address:
0x4044

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, E8, 97, 52, 00, 00, C7, 04, 24, 01, 80, 00, 00, E8, 43, 4F, 00, 00, 56, C7, 04, 24, 00, 00, 00, 00, E8, A6, 52, 00, 00, A3, 88, 5C, 42, 00, 53, C7, 04, 24, 08, 00, 00, 00, E8, 26, 32, 00, 00, A3, 38, 5D, 42, 00, 8D, 85, 84, FE, FF, FF, 51, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A4, B2, 40, 00, E8, D0, 51, 00, 00, 83, EC, 14, C7, 44, 24, 04, A5, B2, 40, 00, C7, 04, 24, 68, 5D...
 
[+]

Code size:
33 KB (33,792 bytes)

The file mein-gutscheincode.exe has been seen being distributed by the following URL.

http://static.crossrider.com/installer/29481/12289/.../49374/.../mein-gutscheincode.exe

Remove mein-gutscheincode.exe - Powered by Reason Core Security