كتاب المعلم 2م ف1... الجزء الثاني.exe

Download Helper

New IT Limited

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application كتاب المعلم 2م ف1... الجزء الثاني.exe by New IT Limited has been detected as adware by 33 anti-malware scanners. The program is a setup application that uses the New IT Desktop Setup installer. The file has been seen being downloaded from rt3.getdownload.net and multiple other hosts.
Publisher:
New IT Limited  (signed and verified)

Product:
Download Helper

Version:
2, 3, 4, 0

MD5:
02c941459922ed4443d898d95049779b

SHA-1:
bca1a1e00db1d015da6114c193b872ebb75b48d4

SHA-256:
59510b7c0fac8d82569957e9430bca6da9d9888940a11aea45ef993daed9919e

Scanner detections:
33 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/23/2024 10:27:30 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.4Shared
7.1.1

Avira AntiVirus
APPL/Downloader.Gen6
7.11.140.132

avast!
Win32:FourShared-D [PUP]
2014.9-140428

AVG
Generic35
2015.0.3490

Comodo Security
Application.Win32.4Shared.G
18030

Dr.Web
Trojan.StartPage.55728
9.0.1.0118

ESET NOD32
Win32/4Shared (variant)
8.9623

Fortinet FortiGate
Riskware/4Shared
4/28/2014

G Data
Win32.Trojan-Downloader.Agent.BA
14.4.24

IKARUS anti.virus
Downloader.Win32.Agent
t3scan.2.2.29

K7 AntiVirus
Trojan
13.176.11623

Malwarebytes
PUP.Optional.4Shared
v2014.04.28.04

McAfee
PUP-FEP!9C6B05D95C89
5600.7146

NANO AntiVirus
Trojan.Win32.StartPage.crgjiq
0.28.0.58873

Reason Heuristics
PUP.NewITLimited.FF
14.4.28.16

Rising Antivirus
PE:PUF.4Shared!1.9C25
23.00.65.14426

Sophos
4Share Downloader
4.98

Trend Micro House Call
TROJ_SPNR.08J813
7.2.118

Trend Micro
TROJ_SPNR.08J813
10.465.28

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
27930

File size:
1.6 MB (1,685,872 bytes)

Product version:
2, 3, 4, 0

Copyright:
Copyright (C) 2013

File type:
Executable application (Win32 EXE)

Bundler/Installer:
New IT Desktop Setup

Common path:
C:\users\{user}\downloads\???? ?????? 2? ?1... ????? ??????.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
11/16/2012 8:16:05 PM

Valid to:
11/16/2013 6:30:34 PM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B2A165690BBAA

File PE Metadata
Compilation timestamp:
5/31/2013 6:00:53 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:UB19SJzur/bc6/nRJ/aOheDkPQcKiwMH5yUKc5thLfrXa7sjybqS9pErw2/6pBLG:UB191bMfRUK5oxJUHz0Dt

Entry address:
0xD836

Entry point:
E8, B2, 45, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 14, 34, 42, 00, 33, C5, 89, 45, FC, F6, 05, E4, 33, 42, 00, 01, 56, 74, 08, 6A, 0A, E8, 47, 35, 00, 00, 59, E8, 6C, 46, 00, 00, 85, C0, 74, 08, 6A, 16, E8, 6E, 46, 00, 00, 59, F6, 05, E4, 33, 42, 00, 02, 0F, 84, CA, 00, 00, 00, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC, FD, FF, FF, 66, 8C, 95, F8, FD, FF, FF, 66, 8C, 8D, EC, FD, FF...
 
[+]

Entropy:
7.6858

Code size:
108 KB (110,592 bytes)

The file كتاب المعلم 2م ف1... الجزء الثاني.exe has been seen being distributed by the following 3 URLs.