openofficesetup.exe

KBM2 Installer

Best Download Manager

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application openofficesetup.exe by Best Download Manager has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from api.kbm2.com. While running, it connects to the Internet address api.yontoo.com on port 80 using the HTTP protocol.
Publisher:
Best Download Manager   (signed by Best Download Manager)

Product:
KBM2 Installer

Version:
2.5.1.0

MD5:
5fe685d4b94c24c2be6f3660bdbe9441

SHA-1:
fecf4ef7fd5b35d33500dd63b137819a11e5f3a4

SHA-256:
454547f018e4af882b1f9575f345cac1c51512dfa336c4e5dfd7ec7c627eb072

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Belongs to the Sambreel/Yontoo progam that inserts various forms of advertising in the user's web browser, installed with minimal or no user consent.

Analysis date:
5/10/2024 3:13:57 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo.BestDownloadManager.Installer (M)
16.2.21.7

File size:
811.6 KB (831,112 bytes)

Product version:
2.5.1.0

Copyright:
(c) Best Download Manager . All rights reserved.

Original file name:
KBM2.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\openofficesetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/24/2013 8:00:00 PM

Valid to:
7/25/2015 7:59:59 PM

Subject:
CN=Best Download Manager, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Best Download Manager, L=Carlsbad, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5F3BBF9CAABCE7C81AB69ABF7371A064

File PE Metadata
Compilation timestamp:
8/7/2013 3:25:15 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:tgq6uX5c0RzWguzZylIAllGVytvHdKme7IZopYK1d3Hav8QZS:tR610ZluglqytYmesZoFj3Hav8QM

Entry address:
0x3A3C0

Entry point:
E8, 0E, 6F, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, D0, 0B, 47, 00, 75, 02, F3, C3, E9, 95, 6F, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 85, F6, 75, 04, 33, C0, EB, 61, 83, 7D, 08, 00, 75, 13, E8, D9, 35, 00, 00, 6A, 16, 5E, 89, 30, E8, 6C, 75, 00, 00, 8B, C6, EB, 48, 83, 7D, 10, 00, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 66, 70, 00, 00, 83, C4, 0C, EB, C7, FF, 75, 0C, 6A, 00, FF, 75, 08, E8, B4, 31, 00, 00, 83, C4, 0C, 83, 7D, 10, 00, 74, BB, 39, 75, 0C, 73, 0E, E8, 8F, 35, 00, 00, 6A...
 
[+]

Entropy:
6.2443

Code size:
342.5 KB (350,720 bytes)

The file openofficesetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to wac.edgecastcdn.net  (72.21.81.13:80)

TCP (HTTP):
Connects to service.yontoo.com  (8.25.35.148:80)

TCP (HTTP):
Connects to api.yontoo.com  (8.25.35.15:80)

Remove openofficesetup.exe - Powered by Reason Core Security