mp3_-_192kbps_oasis_-_stop_the_clocks.exe

Rungnapa Fongkerd

The application mp3_-_192kbps_oasis_-_stop_the_clocks.exe by Rungnapa Fongkerd has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from www.torntv-dl.net and multiple other hosts.
Publisher:
Rungnapa Fongkerd  (signed and verified)

MD5:
d1b86a67716a716058c350c8470e2b24

SHA-1:
42d79dec549511961845fc3a0d7163a97ec9da8f

SHA-256:
ac2acfc4cf0a0ae99e81d45f30e5c22dee21c5821642a19afa521906c24298aa

Scanner detections:
9 / 68

Status:
Adware

Explanation:
The installer bundles additional adware-type offers (ad-supported) that are displayed to the user during setup and typically installed by default. These include web browser ad-injectors.

Analysis date:
4/24/2024 11:26:48 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.BK
875

Bitdefender
Application.Bundler.BK
1.0.20.1280

Dr.Web
Adware.Downware.6586
9.0.1.0218

F-Secure
Application.Bundler.BK
11.2014-13-09_7

G Data
Application.Bundler.BK
14.8.24

Malwarebytes
PUP.Optional.OneClickDownloader.A
v2014.08.06.12

MicroWorld eScan
Application.Bundler.BK
15.0.0.768

Reason Heuristics
PUP.RungnapaFongkerd.f
14.8.12.15

Trend Micro House Call
Suspicious_GEN.F47V0805
7.2.218

File size:
361.1 KB (369,720 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\mp3_-_192kbps_oasis_-_stop_the_clocks.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/28/2014 2:00:00 AM

Valid to:
7/29/2015 1:59:59 AM

Subject:
CN=Rungnapa Fongkerd, OU=Individual Developer, O=No Organization Affiliation, L=Phuket, S=Thailand, C=TH

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5EC13B211C7584BB92BAC58CF7ED1F63

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:EsA7GdHh40I1FyfU9Ln+WRGp3hOYVoIeWRwCZpNVQrXZwTbdb:MGdHSvyfU9T+NdJeqpQDZibp

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file mp3_-_192kbps_oasis_-_stop_the_clocks.exe has been seen being distributed by the following 31 URLs.

http://www.torntv-dl.net/.../_Full.exe

http://www.torntv-downloader.com/.../YouTube_Downloader_Pro_YTD_4.8.0.4_Final_Incl_Crack_-_SceneDL.exe

http://www.torntv-dl.net/common/unibomber.php?pub=yourbittorrent&file=uggc://jjj1.pyvpxqbjaybnqre.pbz/qbjaybnq/cebqhpg_qbjaybnq.cuc?svyrAnzr=uggc://lbheovggbeerag.pbz/.../6311349.gbeerag&name=Xvpx (2014) 720c QIQFpe Evc k264 Grnz QQU~ET

http://www.torntv-dl.net/.../Microsoft_Picture_It_Photo_Premium_10.exe

http://www.torntv-dl.net/.../Princesse_Malgr_Elle_french_dvdrip_XViD_NERD_Upload_[AXE31]Mininova_org_avi.exe

http://www.torntv-dl.net/.../IELTS_Target_band_7_pdf.exe

http://www.torntv-dl.net/.../Nike_Football_The_Last_Game_Amazing_Commercial_2014_720p_HD.exe

http://www.torntv-dl.net/.../El_amanecer_del_planeta_de_los_simios..exe

http://www.torntv-dl.net/.../Clash_Of_The_Titans_(2010)_DVDR_NL_Sub_NLT-Release_(divx).exe

Latest 30 of 31 download URLs

Remove mp3_-_192kbps_oasis_-_stop_the_clocks.exe - Powered by Reason Core Security