xsu1f8a.exe

OfferInstaller

The application xsu1f8a.exe has been detected as a potentially unwanted program by 55 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from direct.downthat.com.
Product:
OfferInstaller

Version:
1.0.0.1

MD5:
579d3e7ab46e28afc81083303053dd9f

SHA-1:
37b6b7a48b31d2de8ce69ec1884eb1118a0d0d68

SHA-256:
c91cbf1a7a5c3cf3cb978ed75cff87c80723e7760b5a9a9c8d76d9a23dcb2afb

Scanner detections:
55 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 11:03:27 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.1204413
682

Avira AntiVirus
TR/Dropper.MSIL.Gen
7.11.218.126

avast!
Win32:GenMaliciousA-FOI [Adw]
2014.9-150325

AVG
Downloader
2016.0.3160

Baidu Antivirus
Adware.MSIL.Imali
4.0.3.15325

Bitdefender
Application.Generic.1204413
1.0.20.420

ESET NOD32
MSIL/Adware.Imali (variant)
9.11346

Fortinet FortiGate
Adware/Imali
3/25/2015

G Data
MSIL.Adware.OfferInstaller
15.3.25

herdProtect (fuzzy)
2015.6.30.1

IKARUS anti.virus
AdWare.MSIL.Imali
t3scan.1.8.6.0

K7 AntiVirus
Adware
13.202.15369

Kaspersky
not-a-virus:AdWare.MSIL.Agent
14.0.0.2294

Malwarebytes
PUP.Optional.OfferInstaller.C
v2015.03.25.06

MicroWorld eScan
Application.Generic.1204413
16.0.0.252

Panda Antivirus
Generic Suspicious
15.03.25.06

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Sophos
Offer Installer
4.98

Trend Micro House Call
Suspicious_GEN.F47V0324
7.2.84

VIPRE Antivirus
MSIL.Adware.Imali
38754

File size:
296.5 KB (303,616 bytes)

Product version:
1.0.0.1

Copyright:
Copyright © 2014

Original file name:
OfferInstaller_dotnet2.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\xsu1f8a.exe

File PE Metadata
Compilation timestamp:
3/19/2015 5:35:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:9gjCcFZT8qbTR7SquD4L8vioH/X8i9DLnHWcefjVo8bS5VDYqL:9gjCEZwgVxGq86oH/MKvnolgh

Entry address:
0x4AE4E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9202

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
292 KB (299,008 bytes)

The file xsu1f8a.exe has been seen being distributed by the following URL.

Remove xsu1f8a.exe - Powered by Reason Core Security