Threat Database Adware Adware.Neoreklami.CG

Adware.Neoreklami.CG

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 8,577
Threat Level: 20 % (Normal)
Infected Computers: 11,460
First Seen: March 22, 2021
Last Seen: June 14, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Adware.Neoreklami.CG
Signature status: No Signature

Known Samples

MD5: 0e179fb2640d5432c633cbc27ce4515d
SHA1: 59fc5b43eeec0aafbc85fe46380d9d8c0dfe8916
SHA256: 17BA8B005A2103C6227D1FADCFAA5610BA8B3AE8889E12B64587060716DB7A6C
File Size: 6.75 MB, 6747136 bytes
MD5: 95ea95cd1f7abf37994c8e7ee8afc53a
SHA1: 1dd97d750112dbb67d7d852d1ac31a4dec72923e
SHA256: 0CDEDE28A5CD94CDCA983EFE94DD59630C365180BCF24B1E0782F6F5FD9F6755
File Size: 7.82 MB, 7821207 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Igor Pavlov
File Description 7z Setup SFX
File Version 9.20
Internal Name 7zS.sfx
Legal Copyright Copyright (c) 1999-2010 Igor Pavlov
Original Filename 7zS.sfx.exe
Product Name 7-Zip
Product Version 9.20

File Traits

  • dll
  • HighEntropy
  • VirtualQueryEx
  • x86

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs4c81.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs4c81.tmp\__data__ Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs4c81.tmp\__data__ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs4c81.tmp\__data__\config.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs4c81.tmp\__data__\config.txt Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs4c81.tmp\install.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs4c81.tmp\install.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs4fdc.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs4fdc.tmp\install.exe Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\7zs4fdc.tmp\install.exe Synchronize,Write Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\59fc5b43eeec0aafbc85fe46380d9d8c0dfe8916_0006747136.,LiQMAxHB
.\Install.exe
.\Install.exe /lsmcdidw "525403" /S

Related Posts

Trending

Most Viewed

Loading...