كتاب مادة الرياضيات للصف الثاني متوسط المنهج المطور الفصل الاول.exe

Download Helper

New IT Limited

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application كتاب مادة الرياضيات للصف الثاني متوسط المنهج المطور الفصل الاول.exe by New IT Limited has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the New IT Desktop Setup installer. The file has been seen being downloaded from rt4.getdownload.net and multiple other hosts.
Publisher:
New IT Limited  (signed and verified)

Product:
Download Helper

Version:
2, 3, 4, 0

MD5:
9c6b05d95c89147c028e1f44d70ab05a

SHA-1:
2678490d147d8b28e45fa669438efb15c8ec6352

SHA-256:
2c28f830e9040b77cd4c78712a2cb443cc34045ff861be7355f3bc8f794469e1

Scanner detections:
21 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 6:44:58 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.4Shared
7.1.1

Avira AntiVirus
APPL/Downloader.Gen6
7.11.140.132

avast!
Win32:FourShared-D [PUP]
2014.9-140401

AVG
Generic35
2015.0.3517

Comodo Security
Application.Win32.4Shared.G
18030

Dr.Web
Trojan.StartPage.55728
9.0.1.091

ESET NOD32
Win32/4Shared (variant)
8.9623

Fortinet FortiGate
Riskware/4Shared
4/1/2014

G Data
Win32.Trojan-Downloader.Agent.BA
14.4.24

IKARUS anti.virus
Downloader.Win32.Agent
t3scan.2.2.29

K7 AntiVirus
Trojan
13.176.11623

Malwarebytes
PUP.Optional.4Shared
v2014.04.01.05

McAfee
PUP-FEP!9C6B05D95C89
5600.7173

NANO AntiVirus
Trojan.Win32.StartPage.crgjiq
0.28.0.58873

Reason Heuristics
PUP.NewITLimited.?
14.4.1.14

Rising Antivirus
PE:PUF.4Shared!1.9C25
23.00.65.14330

Sophos
4Share Downloader
4.98

Trend Micro House Call
TROJ_SPNR.08J813
7.2.91

Trend Micro
TROJ_SPNR.08J813
10.465.01

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
27930

File size:
1.6 MB (1,685,872 bytes)

Product version:
2, 3, 4, 0

Copyright:
Copyright (C) 2013

File type:
Executable application (Win32 EXE)

Bundler/Installer:
New IT Desktop Setup

Common path:
C:\users\{user}\downloads\???? ???? ????????? ???? ?????? ????? ?????? ?????? ????? ?????.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
11/16/2012 8:16:05 PM

Valid to:
11/16/2013 6:30:34 PM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B2A165690BBAA

File PE Metadata
Compilation timestamp:
5/31/2013 6:00:53 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:UB19SJzur/bc6/nRJ/aOheDkPQcKiwMH5yUKc5thLfrXa7sjybqS9pErw2/6pBLG:UB191bMfRUK5oxJUHz0Dt

Entry address:
0xD836

Entry point:
E8, B2, 45, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 14, 34, 42, 00, 33, C5, 89, 45, FC, F6, 05, E4, 33, 42, 00, 01, 56, 74, 08, 6A, 0A, E8, 47, 35, 00, 00, 59, E8, 6C, 46, 00, 00, 85, C0, 74, 08, 6A, 16, E8, 6E, 46, 00, 00, 59, F6, 05, E4, 33, 42, 00, 02, 0F, 84, CA, 00, 00, 00, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC, FD, FF, FF, 66, 8C, 95, F8, FD, FF, FF, 66, 8C, 8D, EC, FD, FF...
 
[+]

Entropy:
7.6862

Code size:
108 KB (110,592 bytes)

The file كتاب مادة الرياضيات للصف الثاني متوسط المنهج المطور الفصل الاول.exe has been seen being distributed by the following 2 URLs.