كتاب التمارين.exe

Download Helper

New IT Limited

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application كتاب التمارين.exe by New IT Limited has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the New IT Desktop Setup installer. The file has been seen being downloaded from rt4.getdownload.net and multiple other hosts.
Publisher:
New IT Limited  (signed and verified)

Product:
Download Helper

Version:
2, 3, 4, 0

MD5:
9af77a49531334f1214fd62c3b203b79

SHA-1:
b5c78f95116b85fdaf43f4bac3ae6263a8f0a926

SHA-256:
f88c0ffb4850ff8eddb1460d54639c19c4d299f3d3480d143d4b19a51db0fbb0

Scanner detections:
21 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/27/2024 12:04:11 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.4Shared
7.1.1

Avira AntiVirus
APPL/Downloader.Gen6
7.11.140.132

avast!
Win32:FourShared-D [PUP]
2014.9-140401

AVG
Generic35
2015.0.3517

Comodo Security
Application.Win32.4Shared.G
18030

Dr.Web
Trojan.StartPage.55728
9.0.1.091

ESET NOD32
Win32/4Shared (variant)
8.9623

Fortinet FortiGate
Riskware/4Shared
4/1/2014

G Data
Win32.Trojan-Downloader.Agent.BA
14.4.24

IKARUS anti.virus
Downloader.Win32.Agent
t3scan.2.2.29

K7 AntiVirus
Trojan
13.176.11623

Malwarebytes
PUP.Optional.4Shared
v2014.04.01.05

McAfee
PUP-FEP!9AF77A495313
5600.7173

NANO AntiVirus
Trojan.Win32.StartPage.crgjiq
0.28.0.58873

Reason Heuristics
PUP.NewITLimited.N
14.4.1.14

Rising Antivirus
PE:PUF.4Shared!1.9C25
23.00.65.14330

Sophos
4Share Downloader
4.98

Trend Micro House Call
TROJ_SPNR.08J813
7.2.91

Trend Micro
TROJ_SPNR.08J813
10.465.01

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
27930

File size:
1.6 MB (1,685,872 bytes)

Product version:
2, 3, 4, 0

Copyright:
Copyright (C) 2013

File type:
Executable application (Win32 EXE)

Bundler/Installer:
New IT Desktop Setup

Common path:
C:\users\{user}\downloads\???? ????????.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
11/16/2012 8:16:05 PM

Valid to:
11/16/2013 6:30:34 PM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B2A165690BBAA

File PE Metadata
Compilation timestamp:
5/31/2013 6:00:53 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:UB19SJzur/bc6/nRJ/aOheDkPQcKiwMH5yUKc5thLfrXa7sjybqS9pErw2/6pBLG:UB191bMfRUK5oxJUHz0Dt

Entry address:
0xD836

Entry point:
E8, B2, 45, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 14, 34, 42, 00, 33, C5, 89, 45, FC, F6, 05, E4, 33, 42, 00, 01, 56, 74, 08, 6A, 0A, E8, 47, 35, 00, 00, 59, E8, 6C, 46, 00, 00, 85, C0, 74, 08, 6A, 16, E8, 6E, 46, 00, 00, 59, F6, 05, E4, 33, 42, 00, 02, 0F, 84, CA, 00, 00, 00, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC, FD, FF, FF, 66, 8C, 95, F8, FD, FF, FF, 66, 8C, 8D, EC, FD, FF...
 
[+]

Entropy:
7.6857

Code size:
108 KB (110,592 bytes)

The file كتاب التمارين.exe has been seen being distributed by the following 2 URLs.

Remove كتاب التمارين.exe - Powered by Reason Core Security