secondoffer2.exe

Creative Island Media, LLC

The software will display additional offers (such as adware) during installation including a browser toolbar/extension as well as advertising injection software (part of the Injekt brand). The application secondoffer2.exe by Creative Island Media has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address update.betterxperience.com on port 80 using the HTTP protocol.
Publisher:
Creative Island Media, LLC  (signed and verified)

MD5:
26daf32362ff836c7bc47fcf339f724c

SHA-1:
8725b459c0c2f5fdd121d424c4bf7378e3806f5d

SHA-256:
9e6b5c6c813c4cc6700974fdb340f8c09c6036295fd27cc55f9d65f0057b6394

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/20/2024 8:39:12 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.NVF
871

avast!
Win32:BHO-AMO [PUP]
2014.9-140916

Bitdefender
Adware.Agent.NVF
1.0.20.1295

Dr.Web
Adware.Plugin.128
9.0.1.0259

Emsisoft Anti-Malware
Adware.Agent.NVF
8.14.09.16.02

ESET NOD32
Win32/ExFriendAlert (variant)
8.9331

F-Secure
Adware.Agent.NVF
11.2014-16-09_3

G Data
Adware.Agent.NVF
14.9.24

IKARUS anti.virus
AdWare.Agent
t3scan.2.2.29

Malwarebytes
PUP.Optional.SearchDonkey.A
v2014.09.16.02

McAfee
Artemis!504226343F98
5600.7005

MicroWorld eScan
Adware.Agent.NVF
15.0.0.777

nProtect
Adware.Agent.NVF
14.01.24.01

Reason Heuristics
PUP.CreativeIslandMedia.M
14.9.16.14

Trend Micro House Call
TROJ_GEN.F47V1220
7.2.259

VIPRE Antivirus
Trojan.Win32.Generic
25746

File size:
3.9 MB (4,044,968 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\dynamicoffer2\secondoffer2.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/21/2013 1:00:00 AM

Valid to:
5/22/2014 12:59:59 AM

Subject:
CN="Creative Island Media, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Creative Island Media, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
68F23F4D2767F6491DEA9186F2E5CB89

File PE Metadata
Compilation timestamp:
6/6/2009 10:41:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:lhJHKRwgEXcYryIX24u91m3O5ZBfClJzGSt74OwpnlrEiY8k6MEnNKpBbhtZpOZX:lhg8XcYeIXU9KOnWWdllrEi0th5OH1

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9735

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to update.betterxperience.com  (54.218.62.24:80)

TCP (HTTP):
Connects to d.pullupdate.com  (54.230.15.37:80)

Remove secondoffer2.exe - Powered by Reason Core Security