{"id":14842,"date":"2013-10-18T00:00:16","date_gmt":"2013-10-18T06:00:16","guid":{"rendered":"https://www.webroot.com/blog/?p=14842"},"modified":"2023-11-01T13:43:10","modified_gmt":"2023-11-01T19:43:10","slug":"rogue-ads-lead-mipony-download-accelerator-fun-moods-toolbar-pua-potentially-unwanted-application","status":"publish","type":"post","link":"https://www.webroot.com/blog/2013\/10\/18\/rogue-ads-lead-mipony-download-accelerator-fun-moods-toolbar-pua-potentially-unwanted-application\/","title":{"rendered":"Rogue ads lead to the &#8216;Mipony Download Accelerator\/FunMoods Toolbar&#8217; PUA (Potentially Unwanted Application)"},"content":{"rendered":"<p><strong>Potentially Unwanted Applications (PUAs)<\/strong> continue to visually social engineer users into installing virtually useless applications. They monetize each and every install by relying on &#8216;bundling&#8217; which often comes in the form of a privacy-violating toolbar or third-party application. We recently intercepted a rogue ad that entices users into downloading the Mipony Download Accelerator that is bundled with the privacy-invading FunMoods toolbar PUA, an unnecessary bargain with the integrity and confidentiality of your PC.<\/p>\n<p><!--more--><\/p>\n<p><strong>Sample screenshot of the landing page:<\/strong><\/p>\n<p><a href=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application.png\"><img decoding=\"async\" loading=\"lazy\" width=\"921\" height=\"913\" class=\"size-full wp-image-14852 aligncenter\" src=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application.png\" alt=\"Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application\" srcset=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application.png 921w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application-150x150.png 150w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application-300x297.png 300w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application-125x125.png 125w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application-32x32.png 32w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application-64x64.png 64w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application-96x96.png 96w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application-128x128.png 128w\" sizes=\"(max-width: 921px) 100vw, 921px\" \/><\/a><\/p>\n<p><strong>Detection rate for the PUA:<\/strong> <a href=\"https:\/\/www.virustotal.com\/en\/file\/3096843008cc4c9363b1e96ccc4618bfc190455fc9266e1740ee1bad528ec71a\/analysis\/1381837813\/\"><strong>MD5: 023e625cbb1b30565d46f7533ddc03db<\/strong><\/a> &#8211; detected by 6 out of 47 antivirus scanners as W32\/InstallCore.R4.gen!Eldorado; Install Core Click run software.<\/p>\n<p><strong>Domain name reconnaissance:<\/strong> ultimatedownloadaccelerator.com &#8211; 50.19.220.248; 174.129.22.118; 23.21.144.61; 23.23.144.245<\/p>\n<p><strong>Upon execution, it phones back to:<\/strong><br \/>\ncdneu.ultimatedownloadaccelerator.com &#8211; 65.254.40.36<br \/>\nos-test.ultimatedownloadaccelerator.com &#8211; 54.244.230.64<br \/>\ncdnus.ultimatedownloadaccelerator.com &#8211; 199.58.87.155<br \/>\nimg.ultimatedownloadaccelerator.com &#8211; 199.58.87.155<\/p>\n<p><strong>Related MD5s part of the same network that are known to have been downloaded from the same IPs, over the last couple of days:<\/strong><br \/>\nMD5: caa5e691d1eddef66294d1323720556e<br \/>\nMD5: 88ba249e0fac7ece69e8a769ec9e81dc<br \/>\nMD5: 748346dc2138aa4927e2ad577c0a97c8<br \/>\nMD5: 78b98bbec669999bd51f7f408d06d9f6<br \/>\nMD5: 7ee56be08401efbc443c286dce641bd6<br \/>\nMD5: 0a6836e3f26e4be1654b18f84191985a<br \/>\nMD5: 3822e38b95cde512aa5a11dc21cd2699<br \/>\nMD5: 2cc18f48633788894e505eaa7b11f6bf<br \/>\nMD5: 02f5346e1ee415de637458be66eb319e<br \/>\nMD5: cdddec958148633578b0574d6551facd<br \/>\nMD5: bc276e312294916fc748937b9e9a6423<br \/>\nMD5: de146519fb5ffe3c5bee07f49ebd0907<br \/>\nMD5: 2d28af1f6bf5115532c19010edbdd463<br \/>\nMD5: df2181cf0b55eebf0f281562314740b1<br \/>\nMD5: 0a6fdc3ecb5da97038df8b28bfaf9581<br \/>\nMD5: df2181cf0b55eebf0f281562314740b1<br \/>\nMD5: 0a6fdc3ecb5da97038df8b28bfaf9581<br \/>\nMD5: 1cd458a9181e1c30cb2b28efd29075cd<br \/>\nMD5: f5976b181cde557f620578eb92535ac7<br \/>\nMD5: b2a7fad9f3f892577d876c74cb221525<br \/>\nMD5: f1242926095907cebd741d8d540567b0<br \/>\nMD5: 2e60e85bfaf1175c2e7ed0390b09ee67<\/p>\n<p><a href=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application_01.png\"><img decoding=\"async\" loading=\"lazy\" width=\"1024\" height=\"2810\" class=\"size-full wp-image-14855 aligncenter\" src=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application_01.png\" alt=\"Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application_01\" srcset=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application_01.png 1024w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application_01-109x300.png 109w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/Download_Accelerator_Mipony_InstallCore_PUA_FunMoods_Toolbar_Potentially_Unwanted_Application_01-373x1024.png 373w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/p>\n<p><strong>Detection rate for the FunMoods Toolbar:<\/strong> <a href=\"https:\/\/www.virustotal.com\/en\/file\/be4283edf1d9be7d7ab4e6e57e7c7e8737585be85a62d427f4965e417af3dd14\/analysis\/1381929038\/\"><strong>MD5: 592f35f9954a7ec4c0b4985857f81ad8<\/strong><\/a> &#8211; detected by 13 out of 48 antivirus scanners as Win32\/InstallCore; PUP.Optional.Funmoods<\/p>\n<p><strong>Once executed, it phones back to:<\/strong><br \/>\nos.funmoodscdn.com (54.245.235.34)<br \/>\ncdneu.funmoodscdn.com (146.185.27.53)<br \/>\ncdnus.funmoodscdn.com (199.58.87.155)<\/p>\n<p><strong>Known to have responded to the same IPs, are also the following domains part of the same infrastructure:<\/strong><br \/>\nos-test.anymusicconverter.com<br \/>\nos-test.coolpdfcreator.com<br \/>\nos-test.extrimdownloadmanager.com<br \/>\nos-test.greataudioconverter.com<br \/>\nos-test.thebestallcodecsapp.com<br \/>\nos-test.thebestcodecpackapp.com<br \/>\nos-test.thebestimageeditorfunapp.com<br \/>\nos-test.thecoolzipextractorapp.com<br \/>\nos-test.thedownloadmanagerapp.com<br \/>\nos-test.thenewzipopenerfun.com<br \/>\nos-test.thepdfcreatorapp.com<br \/>\nos-test.thevideoconverterexclusive.com<br \/>\nos-test.ultimatedownloadaccelerator.com<br \/>\nos-test.unipdfconverter.com<br \/>\nos.50orcdn.com<br \/>\nos.5oftwarescdn.com<br \/>\nos.abiwordapp.com<br \/>\nos.adsearchescdn.com<br \/>\nos.afdlcdn.com<br \/>\nos.afreecodeccdn.com<br \/>\ncdneu.50orcdn.com<br \/>\ncdneu.5oftwarescdn.com<br \/>\ncdneu.adsearchescdn.com<br \/>\ncdneu.afdlcdn.com<br \/>\ncdneu.alcoholsoftcdn.com<br \/>\ncdneu.allmyappscdn.com<br \/>\ncdneu.amazingwebtvcdn.com<br \/>\ncdneu.amniscdn.com<br \/>\ncdneu.anymusicconverter.com<br \/>\ncdneu.anyprotectcdn.com<br \/>\ncdneu.anysendapp.com<br \/>\ncdneu.apponiccdn.com<br \/>\ncdneu.appzeuscdn.com<br \/>\ncdneu.aviracdn.com<br \/>\ncdneu.baixakialtcdn.com<br \/>\ncdneu.baixakialtcdn2.com<br \/>\n2cdneu.baixakicdn.com<br \/>\ncdneu.bestflvplayer.net<br \/>\ncdneu.bestringtonesmaker.com<br \/>\ncdneu.bestvistadownloadscdn.com<\/p>\n<p>Despite the fact that most modern day PUAs include uninstall instructions, our advice is to not install them in the first place, instead, seek a legitimate &#8212; often free but this time fully featured and working &#8212; alternative to their pseudo-unique value propositions.<\/p>\n<p><strong><a href=\"https:\/\/www.webroot.com\/us\/en\/home\/products\/complete\">Webroot\u00a0SecureAnywhere<\/a><\/strong>\u00a0users are proactively protected from these PUAs.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Potentially Unwanted Applications (PUAs) continue to visually social engineer users into installing virtually useless applications. They monetize each and every install by relying on &#8216;bundling&#8217; which often comes in the form of a privacy-violating toolbar or third-party application. We recently intercepted a rogue ad that entices users into downloading the Mipony Download Accelerator that is [&hellip;]<\/p>\n","protected":false},"author":65,"featured_media":17052,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[16309,4811,3871,5267,5257,11067,11021,16301,4295,16305,16303,8933,5253,5255,11657,16307,5721,5291,3529],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/14842"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=14842"}],"version-history":[{"count":15,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/14842\/revisions"}],"predecessor-version":[{"id":32171,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/14842\/revisions\/32171"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/17052"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=14842"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=14842"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=14842"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=14842"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}