Opera.exe

NextRadioTV

The application Opera.exe by NextRadioTV has been detected as adware by 15 anti-malware scanners. According to Microsoft Security Essentials, the software includes a bundle of the DealPly adware which is installed on a user's PC during setup using the InstallCore platform. The file has been seen being downloaded from cdnus.ironcdn.com.
Publisher:
NextRadioTV  (signed and verified)

MD5:
38e489454cd3d065e3f6f33b9f0652b6

SHA-1:
2de6b1d5516e4c5fc8972a5d1f14ef6a6329ebcb

SHA-256:
836c1fc19a70f859cd0dc0a14f22f3d63c47c1562867ce7eae45403b7c59190c

Scanner detections:
15 / 68

Status:
Adware

Explanation:
The installer is a co-bundle distribution utility that might contain adware or various unwanted programs. While the software it is providing is typically clean, the donwload manager offers could be classified as unwanted.

Analysis date:
4/19/2024 11:48:37 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.InstallCore
2013.12.27

Avira AntiVirus
7.11.122.50

Bkav FE
W32.Clod7ea.Trojan
1.3.0.4613

Boost by Reason
Adware.NextRadioTV.F
2013.8.29.2

Dr.Web
Adware.InstallCore.80
9.0.1.0241

Emsisoft Anti-Malware
Trojan.CryptRedol.Gen
8.13.12.29.04

ESET NOD32
Win32/InstallCore.AZ (variant)
7.9190

F-Prot
W32/InstallCore.W.gen
v6.4.7.1.166

IKARUS anti.virus
SoftwareBundler
t3scan.2.2.29

K7 AntiVirus
Trojan
13.174.10644

Malwarebytes
v2013.11.26.06

Microsoft Security Essentials
1.165.247.01

Reason Heuristics
PUP.NextRadioTV.F
14.3.1.0

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.131209

Trend Micro House Call
TROJ_GEN.RCBH1CE
7.2.241

File size:
1.2 MB (1,212,808 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\opera.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/5/2012 5:00:00 PM

Valid to:
8/6/2013 4:59:59 PM

Subject:
CN=NextRadioTV, O=NextRadioTV, STREET=12 rue d Oradour sur Glane, L=Paris, S=IDF, PostalCode=75015, C=FR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F6B0E6D7739316BE77DBC3CE3EF38235

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:B94dAaZ5ZnpwZhcFCjSIpn36G0ZcGbFge4BnCA0nICTgF7P2iV:BqdAM5wkCj6Gs3Jge4BnlgvcFK

Entry address:
0xD64B0

Entry point:
55, 8B, EC, 83, C4, F0, B8, F4, EB, 41, 00, E8, 4A, FE, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7427

Developed / compiled with:
Microsoft Visual C++

Code size:
869.5 KB (890,368 bytes)

The file Opera.exe has been seen being distributed by the following URL.

Remove Opera.exe - Powered by Reason Core Security