nonsens apollo.exe

Stas Kosmov

This is a WebPick installer that bundles (with very minimal user consent) a number of adware browser extensions using the JustPlug.it browser framework. The application nonsens apollo.exe, “Installer for Application fields Software” by Stas Kosmov has been detected as adware by 35 anti-malware scanners. The program is a setup application that uses the WebPick InstalleRex (Tarma) installer. The setup program uses Web-Pick's InstalleRex download manager and installer to bundle potentially unwanted ad-supported software which includes toolbars and browser extensions through a pay-per-install monetization scheme.
Publisher:
Application fields Software  (signed by Stas Kosmov)

Product:
Application fields Software

Description:
Installer for Application fields Software

Version:
2014.6.2.1205

MD5:
fa88a8548daae6eb6419781942b344ed

SHA-1:
62628e2a7d9af5cfbde34e92b8e2183b2e14a53b

SHA-256:
5d44bac16581ec563531cf9b34de717455e166aa9529bba20dfdb99f50f32836

Scanner detections:
35 / 68

Status:
Adware

Explanation:
Uses the InstalleRex from WebPick Internet Holdings to install bundled add-ons including toolbars and other web browser extensions.

Analysis date:
4/26/2024 11:33:00 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11464298
5760947

Agnitum Outpost
Trojan.AntiFW
7.1.1

AhnLab V3 Security
PUP/Win32.TSULoader
2015.04.28

Avira AntiVirus
TR/Visucius.20
3.6.1.96

avast!
Win32:InstalleRex-BX [PUP]
2014.9-150427

AVG
Generic
2016.0.3126

Bitdefender
Trojan.Generic.11464298
1.0.20.585

Bkav FE
W32.FamVT.AntiFWK.Trojan
1.3.0.6379

Clam AntiVirus
Win.Trojan.Installerex-2
0.98/20384

Comodo Security
Application.Win32.InstalleRex.KG
21917

Dr.Web
Trojan.WebPick.2627
9.0.1.0117

Emsisoft Anti-Malware
Trojan.Generic.11464298
9.0.0.4799

ESET NOD32
Win32/InstalleRex.M potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/Generic.AC.4161048
4/27/2015

F-Prot
W32/InstallRex.B
4.6.5.141

F-Secure
Trojan.Generic.11464298
5.13.68

G Data
Trojan.Generic.11464298
15.4.25

IKARUS anti.virus
AdWare.Downloader.InstallRex
t3scan.1.8.9.0

K7 AntiVirus
Unwanted-Program
13.180.12484

Kaspersky
Trojan.Win32.AntiFW
14.0.0.2126

Malwarebytes
PUP.Optional.InstalleRex
v2015.07.28.05

McAfee
PUP-FHQ
5600.6782

MicroWorld eScan
Trojan.Generic.11464298
16.0.0.351

NANO AntiVirus
Riskware.Win32.InfoLeak.cvgqot
0.30.20.1219

Norman
Trojan.Generic.11464298
03.12.2014 13:20:04

nProtect
Trojan/W32.AntiFW.322600
15.04.27.01

Panda Antivirus
PUP/TSUploader
15.04.27.08

Quick Heal
Trojan.AntiFW.A5
4.15.14.00

Reason Heuristics
Adware.WebPick.Installer
15.4.27.16

Rising Antivirus
PE:Trojan.DL.Win32.AntiFW.a!1075355932
23.00.65.15425

Sophos
InstallRex
4.98

Vba32 AntiVirus
AdWare.Agent
3.12.26.3

VIPRE Antivirus
Threat.4150696
29708

Zillya! Antivirus
Trojan.AntiFW.Win32.250
2.0.0.1833

File size:
315 KB (322,600 bytes)

Product version:
1.0.0.3

Copyright:
Copyright © 2014 Application fields Software

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
WebPick InstalleRex (Tarma)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\nonsens apollo.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/24/2013 1:00:00 AM

Valid to:
9/25/2014 12:59:59 AM

Subject:
CN=Stas Kosmov, O=Stas Kosmov, STREET=Levitana 21, L=Kiev, S=Kiev, PostalCode=03083, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7A2834207C5588F506D3CF09661E12F2

File PE Metadata
Compilation timestamp:
3/12/2013 8:51:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:ZrYbUzkuvcBYC47l2xSHyxdphxUIdRyZBBMX9v9y8DBM3i:ZrdkuveY354dH3diBMX9v9Nl

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Entropy:
7.9551

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file nonsens apollo.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

TCP (HTTP):
Connects to c1.stylezip.info  (54.186.255.26:80)

 
http://c1.stylezip.info/?step_id=1&installer_id=20819024&publisher_id=081&source_id=0&page_id=0&country_code=US&locale=US&browser_id=4&download_id=62457072&external_id=0&session_id=124914144&hardware_id=145733168&installer_file_name=nonsens+apollo

Remove nonsens apollo.exe - Powered by Reason Core Security