nero12.exe

NextRadioTV

The application nero12.exe by NextRadioTV has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from cdnus.ironcdn.com.
Publisher:
NextRadioTV  (signed and verified)

MD5:
bddcae7d7c72724a60363c1708da55ce

SHA-1:
79b8ec8d87246793ac09f86b9b8d26c1ec2a36f5

SHA-256:
2d4717d72d6b1a7ab34d8b8a673af26f8a89c5091e28587ec042f024634aabba

Scanner detections:
1 / 68

Status:
Adware

Explanation:
The installer is a co-bundle distribution utility that might contain adware or various unwanted programs. While the software it is providing is typically clean, the donwload manager offers could be classified as unwanted.

Analysis date:
4/23/2024 5:06:29 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.NextRadi (M)
16.4.30.10

File size:
1 MB (1,089,928 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\nero12.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/6/2012 1:00:00 AM

Valid to:
8/7/2013 12:59:59 AM

Subject:
CN=NextRadioTV, O=NextRadioTV, STREET=12 rue d Oradour sur Glane, L=Paris, S=IDF, PostalCode=75015, C=FR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F6B0E6D7739316BE77DBC3CE3EF38235

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:yXtwlk3ZXS+fIGFaJnVV5NlpzNWMYLMqw9jUJXzv3vqp:ANJigIGFaVxpzNWMOM0J7

Entry address:
0xCAC70

Entry point:
55, 8B, EC, 83, C4, F0, B8, 28, 50, 41, 00, E8, E3, FD, FF, FF, 44, 61, 48, 00, 8B, C0, FF, 25, 40, 61, 48, 00, 8B, C0, 53, 56, BE, E0, 55, 48, 00, 83, 3E, 00, 75, 3A, 68, 44, 06, 00, 00, 6A, 00, E8, A8, FF, FF, FF, 8B, C8, 85, C9, 75, 05, 33, C0, 5E, 5B, C3, A1, DC, 55, 48, 00, 89, 01, 89, 0D, DC, 55, 48, 00, 33, D2, 8B, C2, 03, C0, 8D, 44, C1, 04, 8B, 1E, 89, 18, 89, 06, 42, 83, FA, 64, 75, EC, 8B, 06, 8B, 10, 89, 16, 5E, 5B, C3, 90, 89, 00, 89, 40, 04, C3, 8B, C0, 53, 56, 8B, F2, 8B, D8, E8, 9D, FF, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
828 KB (847,872 bytes)

The file nero12.exe has been seen being distributed by the following URL.

Remove nero12.exe - Powered by Reason Core Security