VIPBoxSportsApp.exe

VIPBoxSportsApp

CoolMirage Ltd.

This is part of a CoolMirage installatation, a potentially unwanted program (PUP) that display ads on the computer. The application VIPBoxSportsApp.exe by CoolMirage has been detected as adware by 5 anti-malware scanners. This file is typically installed with the program VipBoxSportsApp by Cool Mirage ltd.. The setup installer will bundle multiple adware offers during download and setup (based on the user's geographical location) including toolbars, extensions and coupon utilities. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www1.installsfiles.com and multiple other hosts.
Publisher:
VIPBoxSports  (signed by CoolMirage Ltd.)

Product:
VIPBoxSportsApp

Version:
2.0.0.1

MD5:
fbafe9383f7641c9f74d33f3f9aaaf84

SHA-1:
e631b509f38f7baf482eb3546b389100b16b0b4e

SHA-256:
6df2bbbf3e8287e34e61954f6586eb5e9b4e754ac3d443e677ef81465563e88b

Scanner detections:
5 / 68

Status:
Adware

Explanation:
Bundles a number of adware programs in the installer.

Analysis date:
4/16/2024 3:16:31 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Downloader-TPG [PUP]
2014.9-140126

Dr.Web
Adware.Downware.625
9.0.1.013

Malwarebytes
PUP.Optional.CoolMirage.A
v2014.01.13.07

Reason Heuristics
PUP.CoolMirage.P
14.8.7.17

VIPRE Antivirus
CoolMirage Ltd
22484

File size:
793 KB (812,024 bytes)

Product version:
2.0.0.1

Copyright:
(c) VIPBoxSports All rights reserved.

Original file name:
VIPBoxSportsApp.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\vipboxsportsapp.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/5/2013 8:00:00 PM

Valid to:
6/6/2014 7:59:59 PM

Subject:
CN=CoolMirage Ltd., O=CoolMirage Ltd., L=Tel Aviv, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
110F603E63C86349A5F243EA06966F33

File PE Metadata
Compilation timestamp:
9/18/2012 6:35:53 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:b/po37S8PkUWrZoHDGTfr2zRWeiG7MHoZWe9dTjItKK6iPxZY:bKkqGTjeseiG7M4zdIt5Y

Entry address:
0x21375

Entry point:
E8, 62, 74, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 58, 59, 87, 04, 24, FF, E0, 58, 59, 87, 04, 24, FF, E0, 8B, FF, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, F1, 13, 42, 00, 6A, 00, FF, 75, 0C, FF, 75, F8, FF, 75, 08, E8, EF, 06, 01, 00, 8B, 45, 0C, 8B...
 
[+]

Entropy:
5.5118

Code size:
203.5 KB (208,384 bytes)

The file VIPBoxSportsApp.exe has been discovered within the following program.

VipBoxSportsApp  by Cool Mirage ltd.
VipBoxSportsApp bundles various potentially unwanted products during installation such as the Yontoo FreeTwit Tube, the Yontoo tooolbar and the Delta Toolbar.
vipboxsportsapp.com
44% remove it
 
Powered by Should I Remove It?

The file VIPBoxSportsApp.exe has been seen being distributed by the following 2 URLs.

Remove VIPBoxSportsApp.exe - Powered by Reason Core Security