supremesavings.exe

Rzmstm

Fun Apps

This is the installer application for a 50onRed advertising supported software package (displays ads in the browser and may hijack the home and search pages of the web browser). The application supremesavings.exe by Fun Apps has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer. It is also typically executed from the user's temporary directory.
Publisher:
Xzcydp  (signed by Fun Apps)

Product:
Rzmstm

Description:
Rulplrud

Version:
1.1.1.1

MD5:
86a05412e343cde4ce4aa69738ecdd81

SHA-1:
c114c2df944ce938797c8affd9600227559873a5

SHA-256:
ef7119745f44309abe0eba130476a2daa29b717ce1667ef9bd66e5c4ba283d2a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/19/2024 11:41:41 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.50OnRed.FunApps.Installer (M)
16.2.14.7

File size:
3.4 MB (3,580,080 bytes)

Copyright:
Kiacbwjkthexqu

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe\dkpc7atwqlulxqy\software\supremesavings.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/3/2013 8:00:00 PM

Valid to:
6/4/2014 7:59:59 PM

Subject:
CN=Fun Apps, O=Fun Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
684B8CFA6A114F5EE6A8115E415BF20A

File PE Metadata
Compilation timestamp:
2/19/2012 10:01:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:1f7/uY796RCRcIss4kSmTmfgel4+yLZfUkmgV2VL4:1LuYJ6cRcIss4WheCfmq2Vk

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 93, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 94, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 94, 42, 00, 56, A3, 40, 7B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 7B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 94, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9961  (probably packed)

Code size:
34.5 KB (35,328 bytes)

Remove supremesavings.exe - Powered by Reason Core Security