viber+4.exe

Viber

Sevas-S LLC

The application viber+4.exe by Sevas-S has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from viber.downloadable.co and multiple other hosts.
Publisher:
Sevas-S LLC  (signed and verified)

Product:
Viber

Version:
1.0.0.0

MD5:
453f19639f585e273eb84a75cba87952

SHA-1:
019964342979b401a3dab6a7a2e9190b25df7ebb

SHA-256:
c91a5e03debac091f3143e134863aa8199b9ab2bcb3ab2429c03e4516adc4110

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
5/21/2024 7:52:55 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.OpenCandy
2014.11.04

Avira AntiVirus
APPL/Downloader.Gen
7.11.182.236

AVG
OpenCandy
2015.0.3301

Baidu Antivirus
Adware.Win32.OpenCandy
4.0.3.14114

Dr.Web
Adware.Downware.8467
9.0.1.0308

ESET NOD32
Win32/JoyDownloader
8.10664

Fortinet FortiGate
Riskware/OpenCandy
11/4/2014

K7 AntiVirus
Unwanted-Program
13.185.13888

Malwarebytes
PUP.Optional.OpenCandy
v2014.11.04.02

McAfee
Artemis!453F19639F58
5600.6957

Reason Heuristics
PUP.SevasS.H
14.11.4.2

VIPRE Antivirus
Sevas-S Installer
34480

File size:
493.7 KB (505,584 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/23/2014 3:00:00 AM

Valid to:
3/26/2015 2:59:59 AM

Subject:
CN=Sevas-S LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sevas-S LLC, L=Kyiv, S=Kyivska oblast, C=UA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4B35AC223F4DB03D3B4C5368983A4B53

File PE Metadata
Compilation timestamp:
5/20/2013 2:53:11 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:YKcXy9+EvdAA8eea2FOn5lCBNTN0aJ4u1pxP2BcUBQnv3J:ICwEVLeaKOnv0Z0pBcUBQnvJ

Entry address:
0x333E

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 30, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, BC, 80, 40, 00, 55, FF, 15, AC, 82, 40, 00, 6A, 08, A3, 78, 4F, 43, 00, E8, A8, 2E, 00, 00, A3, C4, 4E, 43, 00, 55, 8D, 44, 24, 34, 68, B4, 02, 00, 00, 50, 55, 68, F0, B1, 42, 00, FF, 15, 7C, 81, 40, 00, 68, 7C, A3, 40, 00, 68, C0, 3E, 43, 00, E8, 13, 2B, 00, 00, FF, 15, 34, 81, 40, 00, BB, 00, F0, 43, 00, 50, 53, E8, 01, 2B, 00, 00...
 
[+]

Entropy:
7.8760

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file viber+4.exe has been seen being distributed by the following 10 URLs.

http://viber.downloadable.co/get_file/wUiS4WnYccXEwj 8WvauHEA0kxQ8PDK1Ghv2cteQv c8/zOn/j1gwJgELEbtet2lbSb 0FBGZyvZCeLkErY90fo5kNSWXgaQ/CS7Bkf3smnr0raR8oiR1CEXs55ziVBIRjD WGs3hshq9C3wSDbRAOUendXqbj0GbLg3LxwNNK7zXTl1esTceVgwh LuFSw3P9yshbJyTXux8VDNlu0oQIC2M8ivZWNdzcr F oujVtMuZr2zlL ZLh3lymhBM9P5YSxQHP788jEiCdjbbNJV4E9O3YrounkFxlrnE/.../ypIjvig==

http://viber.downloadable.co/get_file/wUiS4WnYccXEwj 8WvauHEA0kxQ8PDK1Ghv2cteQv A8/yOn9np5iNEIJ1XlaL77OHOuyxdSNmmeTbD7Tac8gLNhxcyPYVXDqm3oCFii8C6tgLbbrdPK0jofs55piVRBXzWtCDRn0Ic79WjwW2mLQa5Xi83iPSVeMe0gJFsFMaXlV31tc43EJREwzPiwAC1mcoD4w g1DGCyoFGMlvlmFsf1MJvsOmNXhsu8Geghnx4T5Yz1hhvyb6p/hXj/.../UlK04Ijvig==

http://viber.downloadable.co/get_file/.../4O h1vyfKh2kz6tQMVe5NXiGi37uNKamCYyZrFRTsc3P3Ux5arnRFg0nB3p3dxAEinhAgr0oJvvig==

http://viber.ar.downloadable.co/get_file/wUiS4WnYccXAwj 1RrjxCgghkkVxZmbzR1 xcteQv A8/zyn9np5iNEMJ1Xmb6n3fHm ykYcdnGHWOOmEqc20bIjzsedDR7Fpmy4UBe /Tnjmf6SpNzSgyUS88BykV4BXnCtGGgqyJd8vDnxGWmaSq5ey8PzPHQNa7MgaUFbIaS0XHx1aszOIxwljLPvUSwjcpenma1sTDyouQPFnfttAJK9dcurZnof1cK3D6p9yw8etIL8jlO7ZKl/.../V91Wrc2 SWvss5OZkj4rJLxHT5ZrYCN2ounkFxtghATWjo8RUTzlGFi79ojvig==

http://viber.ar.downloadable.co/get_file/wUiS4WnYccXBwj pXP7oQlssmVQ9fDKhEgqnKJyK97Yk5jz0o2xzz9gHJEbiYbC/NXC20g0BZnGHWOOlEqc2xKtrh8ycBwaDq3a7TBqm8T791 fa7dPdm3EN MdlwUdJF3ykACw1zZc79WjwX2mLRbxewc/zPHQNbrMgeUdTZ/q1RHE8cs3ENBkhiLPvUSwhcpekiLFgHGL5uFvOlu0KXcDoMtKqcSQUitO2XuMmlQ9Krpr2zlL/ZLgyznLyXIge/Mz4SXrjodfJzj4rJLxFT5Y/.../rBwfhoojvig==

Remove viber+4.exe - Powered by Reason Core Security