Threat Database Adware Adware.Multibar

Adware.Multibar

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 13,463
Threat Level: 20 % (Normal)
Infected Computers: 789
First Seen: December 16, 2012
Last Seen: February 5, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Adware.Multibar
Signature status: Root Not Trusted

Known Samples

MD5: 9f88c8f927d22d9cb3ae0ed8b7442ae4
SHA1: e944b137aeacc4006f379bbf359ce37849fa2cd7
SHA256: DA6D29A59C4E48D343AC822009ED03C80FADEBA3BA62451CC50D678F76CA44C1
File Size: 251.49 KB, 251488 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name sipgate
File Description softphone
File Version 1.16.3
Legal Copyright Copyright © 2021 sipgate
Product Name sipgate softphone
Product Version 1.16.3

Digital Signatures

Signer Root Status
Sipgate GmbH USERTrust RSA Certification Authority Root Not Trusted
Sipgate GmbH USERTrust RSA Certification Authority Root Not Trusted

File Traits

  • Installer Manifest
  • Nullsoft Installer
  • x86

Block Information

Total Blocks: 100
Potentially Malicious Blocks: 0
Whitelisted Blocks: 100
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.LA
  • Brute.BHA
  • Chapak.HBX
  • CobaltStrike.GI
  • MSILZilla.TC
Show More
  • Trojan.Agent.Gen.VN

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsjab11.tmp\nsprocess.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsjab11.tmp\stdutils.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsjab11.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsjab11.tmp\winshell.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~nsua.tmp\un_a.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Users\Obgpriey\AppData\Local\Temp\~nsuA.tmp\Un_A.exe" _?=c:\users\user\downloads\

Trending

Most Viewed

Loading...