setup.exe

Scan Tack

This is the installer and setup program from the Scan Tack branded Yontoo adware web browser extension. This adware injects various forms of advertisements in the user's web browser based on the HTML content and URLs viewed. Ad include banners, in-line context text links, coupons, and search. The program will install an auto-updating background service that will update the software with additional features. The application setup.exe by Scan Tack has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Scan Tack  (signed and verified)

MD5:
99c5814bce16fe4a7d11c9fdd6d2e2bf

SHA-1:
5cb72760137470f1b6e539c8dd130ea91616a8e8

SHA-256:
163f13480b4bfaa45a5f03ed330d12a42c0cd81f7acdd6048ec4bfe354385d4e

Scanner detections:
21 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/25/2024 6:48:57 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Agent
7.1.1

Avira AntiVirus
APPL/BrowseFox.Gen2
7.11.144.172

AVG
MalSign.Generic
2015.0.3495

Baidu Antivirus
Adware.Win32.Agent
4.0.3.14423

Comodo Security
Application.Win32.Altbrowse.AK
18148

Dr.Web
Trojan.BPlug.35
9.0.1.0113

ESET NOD32
Win32/BrowseFox (variant)
8.9704

Fortinet FortiGate
Adware/Agent
4/23/2014

G Data
Win32.Application.BrowseFox
14.4.24

IKARUS anti.virus
not-a-virus:AdWare.Win32.Agent
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.176.11833

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3970

Malwarebytes
PUP.Optional.ScanTack.A
v2014.04.23.10

McAfee
Artemis!99C5814BCE16
5600.7151

NANO AntiVirus
Riskware.Win32.Agent.cuenda
0.28.0.59492

Reason Heuristics
PUP.Installer.ScanTack.F
14.4.23.22

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.14421

Sophos
Generic PUA FM
4.98

SUPERAntiSpyware
Adware.BrowseFox/Variant
10647

Trend Micro House Call
TROJ_GEN.F47V0421
7.2.113

VIPRE Antivirus
Yontoo
28486

File size:
2 MB (2,088,616 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/22/2014 11:00:00 AM

Valid to:
1/23/2015 10:59:59 AM

Subject:
CN=Scan Tack, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Scan Tack, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
44D91A3142283CE62B23F23C84838B0D

File PE Metadata
Compilation timestamp:
12/6/2009 9:52:01 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:EQZF8GqTY94bmg2z0g+2qJLQmws1oCS25yDLsO+BQZl8:1ZuGHIez0zumwsFSq4RjZO

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 6F, 44, 00, E8, F1, 2B, 00, 00, A3, 84, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 2E, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9974

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to wac.edgecastcdn.net  (72.21.81.13:80)

TCP (HTTP):
Connects to service.yontoo.com  (8.25.35.148:80)

TCP (HTTP):
Connects to api.yontoo.com  (8.25.35.15:80)

Remove setup.exe - Powered by Reason Core Security