1st primary audio files education4iq (h.k.).rar__15047_i1707095447_il543448.exe

LLC

The application 1st primary audio files education4iq (h.k.).rar__15047_i1707095447_il543448.exe by LLC has been detected as adware by 6 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from mymediadownloadseighteen.com.
Publisher:
LLC   (signed and verified)

MD5:
8db7ccdd1fc02e048a277e24682740af

SHA-1:
ca97e0111d7cd5a3ac9e42133dc281443385c495

SHA-256:
a88a5496349ea77d5c6df35cea587d5b620512bc6d9500138afe673e37f31744

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
5/17/2025 2:33:42 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Amonetize
2015.10.13

Baidu Antivirus
PUA.Win32.Amonetize
4.0.3.151013

ESET NOD32
Win32/Amonetize.KC potentially unwanted (variant)
9.12399

Panda Antivirus
Trj/Genetic.gen
15.10.13.11

Reason Heuristics
PUP.Amonitize (M)
15.10.13.11

Rising Antivirus
PE:Malware.RDM.15!5.15[F1]
23.00.65.151011

File size:
833.7 KB (853,728 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/17/2015 3:00:00 AM

Valid to:
9/17/2016 2:59:59 AM

Subject:
CN="LLC ""B2B SOFT UA""", OU=IT, O="LLC ""B2B SOFT UA""", STREET="Bud. 28/2 kv. N.P. N.43, vul.Grushevskogo", L=Kyyiv, S=Kyyiv, PostalCode=01010, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B05F3B21ACBEADA74CFBA86960BDBA4E

File PE Metadata
Compilation timestamp:
10/13/2015 2:04:30 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:2sQHcr1IUSkPIx0C4cN9VOyt5vVGXhJN66dqzeN1OmGJ9KcVMPDuvfyFZeCQ:wcraneJLc1HQUy1CVMSiiCQ

Entry address:
0x3E27

Entry point:
E8, 00, 00, 00, 00, 83, 04, 24, 0F, FF, 34, 24, 81, 04, 24, F8, 28, 00, 00, C3, E9, 28, FD, FF, FF, 55, 8B, EC, FF, 15, 5C, 10, 42, 00, 6A, 01, A3, 24, B5, 42, 00, E8, BC, 2F, 00, 00, FF, 75, 08, E8, 37, 2F, 00, 00, 83, 3D, 24, B5, 42, 00, 00, 59, 59, 75, 08, 6A, 01, E8, A2, 2F, 00, 00, 59, 68, 09, 04, 00, C0, E8, 00, 00, 00, 00, 83, 04, 24, 0F, FF, 34, 24, 81, 04, 24, F6, 2E, 00, 00, C3, 59, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 64, 70, 01, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, 08...
 
[+]

Entropy:
7.2259

Code size:
127.5 KB (130,560 bytes)

The file 1st primary audio files education4iq (h.k.).rar__15047_i1707095447_il543448.exe has been seen being distributed by the following URL.