4s6f8.exe

Must have files

Pvl Point

The application 4s6f8.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from www.inditedexplanatory.webcam.
Publisher:
Pvl Point

Product:
Must have files

Description:
oXORwzg

Version:
163.203.79.148

MD5:
f02ffb837ae0c18fd94735d32d9dd855

SHA-1:
526e331445a1266308309fff00003c0545b909b2

SHA-256:
3e03df7f2b3342738c69f201f7f136a9cb470577fdd1adcf172a130710813f3d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
5/20/2024 7:49:17 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.InstallMonetizer.PvlPoint.Meta (M)
16.7.13.9

File size:
701.5 KB (718,336 bytes)

Product version:
163.203.79.148

Copyright:
JgIQg5h

Trademarks:
Kocl

Original file name:
tinyinstall.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\4s6f8.exe

File PE Metadata
Compilation timestamp:
7/12/2016 12:25:00 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:B9t1xJHVXwOUNXTGLReSspaJhG06wTlxTh/3U12iAwHKg/J0EZr:DXHGOUNX6ThJhG06wXThs12iAoJ0EZ

Entry address:
0x589D

Entry point:
E8, 1A, 54, 00, 00, E9, 39, FE, FF, FF, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, 14, E9, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, 14, E9, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, A0, 00, 00, 00, C7, 06, FC, E8, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 44, 00, 00, 00, C7, 06, FC, E8, 41, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1...
 
[+]

Entropy:
7.0782

Code size:
110.5 KB (113,152 bytes)

The file 4s6f8.exe has been seen being distributed by the following URL.

Remove 4s6f8.exe - Powered by Reason Core Security