openoffice.exe

openoffice

REDACCENIR SL

The application openoffice.exe by REDACCENIR SL has been detected as adware by 29 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from d1w467en2eqqh2.cloudfront.net.
Publisher:
REDACCENIR SL  (signed and verified)

Product:
openoffice

Version:
2.2.45.0

MD5:
c1f5a1a086d7c079626c9dcf996fe039

SHA-1:
738aeb8723fb75a3751b8614944b236221c8cc54

SHA-256:
66a37eec4989cdaf6c5a2b5f01039923d9b44df10416c44bc255f6563fcf3889

Scanner detections:
29 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/27/2024 1:13:28 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Solimba.1
579

Agnitum Outpost
Trojan.Adware
7.1.1

Avira AntiVirus
APPL/Solimba.B
7.11.177.204

avast!
NSIS:Solimba-B [PUP]
2014.9-150705

Bitdefender
Gen:Variant.Adware.Solimba.1
1.0.20.930

Clam AntiVirus
WIN.Adware.Solimba-3
0.98/21411

Comodo Security
Application.Win32.Solimba.K
19774

Dr.Web
Tool.DownLoader.46
9.0.1.0186

Emsisoft Anti-Malware
Gen:Variant.Adware.Solimba
8.15.07.05.04

ESET NOD32
MSIL/Solimba
9.10550

Fortinet FortiGate
Adware/Solimba
7/5/2015

F-Prot
W32/Solimba.B.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Solimba.1
11.2015-05-07_1

G Data
Gen:Variant.Adware.Solimba
15.7.24

K7 AntiVirus
Unwanted-Program
13.183.13642

Kaspersky
not-a-virus:AdWare.MSIL.Solimba
14.0.0.1781

Malwarebytes
Adware.Solimba
v2015.07.05.04

McAfee
Artemis!C1F5A1A086D7
5600.6713

MicroWorld eScan
Gen:Variant.Adware.Solimba.1
16.0.0.558

NANO AntiVirus
Riskware.Win32.Solimba.cudvtq
0.28.2.62483

Norman
Solimba.DIMI
11.20150705

Panda Antivirus
Adware/Solimba
15.07.05.04

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Quick Heal
AdWare.MSIL.r3 (Not a Virus)
7.15.14.00

Reason Heuristics
PUP.REDACCENIR.Installer (M)
15.7.5.16

Rising Antivirus
PE:Trojan.Win32.Generic.1389F772!327808882
23.00.65.15703

SUPERAntiSpyware
Trojan.Agent/Gen-Solimba
9772

Vba32 AntiVirus
Signed-Adware.InstallCore
3.12.26.3

VIPRE Antivirus
DownloadMR
33854

File size:
177.7 KB (181,968 bytes)

Copyright:
(c) 2010 (Build:2012-11-15 19:14)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Common path:
C:\users\{user}\downloads\openoffice.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/22/2011 7:00:00 PM

Valid to:
12/22/2012 6:59:59 PM

Subject:
CN=REDACCENIR SL, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=REDACCENIR SL, L=Terrassa, S=Barcelona, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
71215C0E2FF8F33A61438B1BB7D0D7D3

File PE Metadata
Compilation timestamp:
8/30/2011 10:46:24 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.21

CTPH (ssdeep):
3072:onOn7t7XpdpCCTg/sxFgJD2SCdQaZtRpzcrGooJhmIEsqYGz1KRotB7T57fkuUAV:oKpdcCrTqAmaZtRpzcy/7PNGzbZTFZdV

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 83, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 84, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 84, 42, 00, 56, A3, 40, 6B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 6B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 84, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Code size:
34.5 KB (35,328 bytes)

The file openoffice.exe has been seen being distributed by the following URL.

Remove openoffice.exe - Powered by Reason Core Security