as patricinhas de beverly hills dublado ver filme online.exe

MIDIA TECHNOLOGIES LLC

The application as patricinhas de beverly hills dublado ver filme online.exe by MIDIA TECHNOLOGIES has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Midia Downloader installer. The file has been seen being downloaded from www.klumag.net.
Publisher:
MIDIA TECHNOLOGIES LLC  (signed and verified)

MD5:
aefa73b09deaa4968768148d3cb5fcbb

SHA-1:
b0224333698ed7e9f8b8da50c70e8b05b5e0c638

SHA-256:
6455caf52cbb03e202299600171ffee9de7b4a04a6c5d677394464dae6bb22f9

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/27/2024 10:32:52 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Midia Technologies (M)
16.8.12.6

File size:
768.6 KB (787,064 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Midia Downloader

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\as patricinhas de beverly hills dublado ver filme online.exe

Digital Signature
Authority:
Starfield Technologies, Inc.

Valid from:
4/11/2014 3:45:06 PM

Valid to:
4/11/2015 3:45:06 PM

Subject:
CN=MIDIA TECHNOLOGIES LLC, O=MIDIA TECHNOLOGIES LLC, L=Lewes, S=Delaware, C=US

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0475D122CC437D

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:aYFJs4k18KM6TggBKUn/3H/j4rWDC9eRZXLGxZ5m9faEVGe5:XzO1W6Tg7U/fmW1riD5m9faCGe5

Entry address:
0x93850

Entry point:
55, 8B, EC, 83, C4, F0, B8, 30, 34, 91, 26, E8, 40, 29, F7, FF, A1, D0, 64, 91, 26, 8B, 00, E8, 04, 7A, FC, FF, A1, D0, 64, 91, 26, 8B, 00, BA, C8, 38, 91, 26, E8, EB, 75, FC, FF, 8B, 0D, A4, 60, 91, 26, A1, D0, 64, 91, 26, 8B, 00, 8B, 15, A8, 25, 91, 26, E8, F3, 79, FC, FF, 8B, 0D, 38, 66, 91, 26, A1, D0, 64, 91, 26, 8B, 00, 8B, 15, E4, FE, 8F, 26, E8, DB, 79, FC, FF, A1, D0, 64, 91, 26, 8B, 00, E8, 4F, 7A, FC, FF, E8, 8A, 05, F7, FF, 00, 00, FF, FF, FF, FF, 11, 00, 00, 00, 50, 72, 6F, 74, 65, 74, 6F, 72...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
586.5 KB (600,576 bytes)

The file as patricinhas de beverly hills dublado ver filme online.exe has been seen being distributed by the following URL.

http://www.klumag.net/ids/.../As Patricinhas De Beverly Hills Dublado Ver Filme Online.exe