Supreme-Savings.exe

Klnedb

Innovative Apps

This is the installer application for a 50onRed advertising supported software package (displays ads in the browser and may hijack the home and search pages of the web browser). The application Supreme-Savings.exe by Innovative Apps has been detected as adware by 11 anti-malware scanners. This is a setup program which is used to install the application. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links. The file has been seen being downloaded from staticrr.secdls.com.
Publisher:
Eamjziq  (signed by Innovative Apps)

Product:
Klnedb

Description:
Ixrsrsnpitczs

Version:
1.1.1.1

MD5:
991998e1e4e3de0e11089344cecc00f7

SHA-1:
4e27bb167c112435e1a4c2b316c5b0c50b409e03

SHA-256:
fa1611b8f8212d0cf186639102c5b150b39965230628aaa647cba890ed3c9ef7

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
4/26/2024 3:17:34 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Installer-M [Adw]
2014.9-130828

Boost by Reason
Trojan.Adw.InnovativeApps.P
2013.8.28.23

Comodo Security
Heur.Suspicious
17082

Dr.Web
Adware.Downware.1054
9.0.1.0240

ESET NOD32
Win32/Packed.ScrambleWrapper
7.8900

Malwarebytes
PUP.Optional.CrossRider
v2013.11.27.01

McAfee
Artemis!991998E1E4E3
5600.7271

Reason Heuristics
PUP.InnovativeApps.P
14.8.7.17

Sophos
AppRider
4.93

Trend Micro House Call
TROJ_GEN.F47V0606
7.2.240

VIPRE Antivirus
GamePlayLabs
22252

File size:
3.4 MB (3,578,144 bytes)

Copyright:
Wdvcgojxwk

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\supreme-savings.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
1/8/2013 4:00:00 PM

Valid to:
1/9/2014 3:59:59 PM

Subject:
CN=Innovative Apps, O=Innovative Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5419E32FDAD7A6E5666A35066C5EAAC5

File PE Metadata
Compilation timestamp:
1/5/2010 4:09:32 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
49152:FSsIY/T3dtguMm6dbITb7Nc14gEOPoYDA2mhpl4qqImyHfQCuirkiaMD/3cgaSMO:wsIY/mmAbuhc1XPoPYAHo4kOE18

Entry address:
0x4044

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, E8, 97, 52, 00, 00, C7, 04, 24, 01, 80, 00, 00, E8, 43, 4F, 00, 00, 56, C7, 04, 24, 00, 00, 00, 00, E8, A6, 52, 00, 00, A3, 88, 5C, 42, 00, 53, C7, 04, 24, 08, 00, 00, 00, E8, 26, 32, 00, 00, A3, 38, 5D, 42, 00, 8D, 85, 84, FE, FF, FF, 51, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A4, B2, 40, 00, E8, D0, 51, 00, 00, 83, EC, 14, C7, 44, 24, 04, A5, B2, 40, 00, C7, 04, 24, 68, 5D...
 
[+]

Entropy:
7.9967  (probably packed)

Code size:
33 KB (33,792 bytes)

The file Supreme-Savings.exe has been seen being distributed by the following URL.

Remove Supreme-Savings.exe - Powered by Reason Core Security