plants_vs_zombies.exe

MAFER INTERNET SL

The application plants_vs_zombies.exe by MAFER INTERNET SL has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from storage.toggle.com.
Publisher:
MAFER INTERNET SL  (signed and verified)

MD5:
a6a82f5661be26644233ccdd47a58a34

SHA-1:
a0500c15ddfb824ec607d68f0d5d61c675edb396

SHA-256:
844b4881a46b54e9920cd8463b86593ecbe9ee3a740caa072c92437d228cf2a6

Scanner detections:
8 / 68

Status:
Adware

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
4/25/2024 3:19:05 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen
8.3.1.6

AVG
Toolbar.Babylon
2016.0.3081

Dr.Web
Adware.Downware.1161
9.0.1.05190

ESET NOD32
Win32/Toggle.H potentially unwanted application
7.0.302.0

K7 AntiVirus
Unwanted-Program
13.205.16218

NANO AntiVirus
Riskware.Nsis.Adware.dpyzfo
0.30.24.2086

Reason Heuristics
PUP.Installer.MAFERINTERNET
15.6.11.21

VIPRE Antivirus
Threat.4786062
40830

File size:
106 KB (108,568 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\plants_vs_zombies.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
8/6/2012 3:00:00 AM

Valid to:
10/10/2013 2:00:00 PM

Subject:
CN=MAFER INTERNET SL, O=MAFER INTERNET SL, L=Villaviciosa de Odon, C=ES

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0AEB661A7237B4F0B7B4E4E81EE53B63

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:GgXdZt9P6D3XJk45VHQnn3UQwIAwGZ6YH99wh1Zm:Ge34aqwn/bG196/m

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.4673

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file plants_vs_zombies.exe has been seen being distributed by the following URL.

Remove plants_vs_zombies.exe - Powered by Reason Core Security