6y42v.exe

Smart Inst

Old Tramolt

The application 6y42v.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from www.akeepalpably.science.
Publisher:
Old Tramolt

Product:
Smart Inst

Description:
cmpnnt

Version:
91.185.195.228

MD5:
d7e6d62200b46618560098c28c2ea7c8

SHA-1:
05ad18939132004a7ac77091601f7627930185b9

SHA-256:
d487bc224de6cdafee60256ba52bd2236ba9e690dbb8fb869b47249c69ae2a02

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
5/5/2024 6:27:10 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.InstallMonetizer.OldTramo.Meta (M)
16.6.2.12

File size:
1.1 MB (1,111,552 bytes)

Product version:
91.185.195.228

Copyright:
CL2016

Trademarks:
Pepcyc

Original file name:
tinyinstall.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\6y42v.exe

File PE Metadata
Compilation timestamp:
6/2/2016 4:04:48 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:TT7iM7Z7ribYb3gadDOLcmbaIclQMbZDhTtPr7aTx:TCSZ6bYLgCpme1KkDhBzQ

Entry address:
0x7BC6

Entry point:
E8, 43, 41, 00, 00, E9, 89, FE, FF, FF, 6A, 00, FF, 15, 20, 00, 41, 00, C3, FF, 15, 34, 00, 41, 00, C2, 04, 00, 8B, FF, 56, FF, 35, 78, 43, 41, 00, FF, 15, 38, 00, 41, 00, 8B, F0, 85, F6, 75, 1B, FF, 35, D0, 52, 41, 00, FF, 15, 24, 00, 41, 00, 8B, F0, 56, FF, 35, 78, 43, 41, 00, FF, 15, 3C, 00, 41, 00, 8B, C6, 5E, C3, A1, 74, 43, 41, 00, 83, F8, FF, 74, 16, 50, FF, 35, D8, 52, 41, 00, FF, 15, 24, 00, 41, 00, FF, D0, 83, 0D, 74, 43, 41, 00, FF, A1, 78, 43, 41, 00, 83, F8, FF, 74, 0E, 50, FF, 15, 40, 00, 41...
 
[+]

Entropy:
7.2339

Code size:
60.5 KB (61,952 bytes)

The file 6y42v.exe has been seen being distributed by the following URL.

Remove 6y42v.exe - Powered by Reason Core Security