4shared__15334_i1749543187_il16.exe

LLC

The application 4shared__15334_i1749543187_il16.exe by LLC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from www.ice7water.info.
Publisher:
LLC   (signed and verified)

MD5:
72269b3663f91f2a4d635525de935264

SHA-1:
2ae175989a89ad61d4dd3332389c3c1a5cbc45d2

SHA-256:
704dfb7910e5a59bb96b5f5688173e53e0046fd6b1434faff116438bcba457a2

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
2/12/2026 10:50:04 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize (M)
15.11.20.1

File size:
778.7 KB (797,360 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\programs\4shared__15334_i1749543187_il16.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/19/2015 4:30:00 AM

Valid to:
9/19/2016 4:29:59 AM

Subject:
CN="LLC ""KIPER - SOFT""", O="LLC ""KIPER - SOFT""", STREET=Bud. 6 vul.Pryashivska-Bichna, L=Mukacheve, S=Zakarpatska, PostalCode=89600, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00974D43D1437CC68DB94B6DEBA5289FEC

File PE Metadata
Compilation timestamp:
11/20/2015 3:41:56 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:eqzFnltIHkuOVMf/Yw/8kVpXipo1J9S9rhQrRq:euhYwAFrypo1J9SVhgRq

Entry address:
0x3273

Entry point:
E8, 00, 00, 00, 00, 83, 04, 24, 0F, FF, 34, 24, 81, 04, 24, AE, 16, 00, 00, C3, E9, 57, FE, FF, FF, 55, 8B, EC, FF, 15, 1C, F0, 40, 00, 6A, 01, A3, 44, 83, 41, 00, E8, 86, 1D, 00, 00, FF, 75, 08, E8, 16, 1B, 00, 00, 83, 3D, 44, 83, 41, 00, 00, 59, 51, 59, 59, 75, 08, 6A, 01, E8, 6A, 1D, 00, 00, 59, 68, 09, 04, 00, C0, E8, E0, 1A, 00, 00, 51, 59, 59, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 99, 63, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, 28, 81, 41, 00, 89, 0D, 24, 81, 41, 00, 89, 15...
 
[+]

Entropy:
7.3645

Code size:
56.5 KB (57,856 bytes)

The file 4shared__15334_i1749543187_il16.exe has been seen being distributed by the following URL.

Remove 4shared__15334_i1749543187_il16.exe - Powered by Reason Core Security