كتاب المعلم 2م ف1... الجزء الأول.exe

Download Helper

New IT Limited

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application كتاب المعلم 2م ف1... الجزء الأول.exe by New IT Limited has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the New IT Desktop Setup installer. The file has been seen being downloaded from rt4.getdownload.net and multiple other hosts.
Publisher:
New IT Limited  (signed and verified)

Product:
Download Helper

Version:
2, 3, 4, 0

MD5:
ce93d5edc1e1794746788c3d53db543f

SHA-1:
6d9886f5300c5671b0a6cd928c1dd64e87e283f8

SHA-256:
3130534ba4886ba1286f6c41e32a1b050181c78bd6f411aaad22aa15f80791b7

Scanner detections:
21 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/18/2024 5:55:30 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.4Shared
7.1.1

Avira AntiVirus
APPL/Downloader.Gen6
7.11.140.132

avast!
Win32:FourShared-D [PUP]
2014.9-140428

AVG
Generic35
2015.0.3490

Comodo Security
Application.Win32.4Shared.G
18030

Dr.Web
Trojan.StartPage.55728
9.0.1.0118

ESET NOD32
Win32/4Shared (variant)
8.9623

Fortinet FortiGate
Riskware/4Shared
4/28/2014

G Data
Win32.Trojan-Downloader.Agent.BA
14.4.24

IKARUS anti.virus
Downloader.Win32.Agent
t3scan.2.2.29

K7 AntiVirus
Trojan
13.176.11623

Malwarebytes
PUP.Optional.4Shared
v2014.04.28.05

McAfee
PUP-FEP!9C6B05D95C89
5600.7146

NANO AntiVirus
Trojan.Win32.StartPage.crgjiq
0.28.0.58873

Reason Heuristics
PUP.NewITLimited.EE
14.4.28.17

Rising Antivirus
PE:PUF.4Shared!1.9C25
23.00.65.14426

Sophos
4Share Downloader
4.98

Trend Micro House Call
TROJ_SPNR.08J813
7.2.118

Trend Micro
TROJ_SPNR.08J813
10.465.28

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
27930

File size:
1.6 MB (1,685,872 bytes)

Product version:
2, 3, 4, 0

Copyright:
Copyright (C) 2013

File type:
Executable application (Win32 EXE)

Bundler/Installer:
New IT Desktop Setup

Common path:
C:\users\{user}\downloads\???? ?????? 2? ?1... ????? ?????.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
11/16/2012 8:16:05 PM

Valid to:
11/16/2013 6:30:34 PM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B2A165690BBAA

File PE Metadata
Compilation timestamp:
5/31/2013 6:00:53 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:UB19SJzur/bc6/nRJ/aOheDkPQcKiwMH5yUKc5thLfrXa7sjybqS9pErw2/6pBLG:UB191bMfRUK5oxJUHz0Dt

Entry address:
0xD836

Entry point:
E8, B2, 45, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 14, 34, 42, 00, 33, C5, 89, 45, FC, F6, 05, E4, 33, 42, 00, 01, 56, 74, 08, 6A, 0A, E8, 47, 35, 00, 00, 59, E8, 6C, 46, 00, 00, 85, C0, 74, 08, 6A, 16, E8, 6E, 46, 00, 00, 59, F6, 05, E4, 33, 42, 00, 02, 0F, 84, CA, 00, 00, 00, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC, FD, FF, FF, 66, 8C, 95, F8, FD, FF, FF, 66, 8C, 8D, EC, FD, FF...
 
[+]

Entropy:
7.6859

Code size:
108 KB (110,592 bytes)

The file كتاب المعلم 2م ف1... الجزء الأول.exe has been seen being distributed by the following 2 URLs.