aviny-prayer-times.exe

Aviny Prayer Times

موسسه فرهنگی هنری رسانه

The application aviny-prayer-times.exe has been detected as a potentially unwanted program by 20 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. It uses Web-Pick's InstalleRex download manager and installer to bundle potentially unwanted ad-supported software which includes toolbars and browser extensions through a pay-per-install monetization scheme. The file has been seen being downloaded from dl.aviny.com.
Publisher:
موسسه فرهنگی هنری رسانه

Product:
Aviny Prayer Times

Description:
Installer

Version:
2013.8.1.1216

MD5:
5d32f9c450cd0118a9bdde028d946257

SHA-1:
14d4253e70788510cb68d0b8611e547cae7da5d3

SHA-256:
c7014f8ca7fd9fde7780af5a637724df1e7a0df9d0f6403754bedd88a8e75725

Scanner detections:
20 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstalleRex from WebPick Internet Holdings to install bundled add-ons including toolbars and other web browser extensions.

Analysis date:
5/6/2024 3:48:56 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstalleRex
7.1.1

Avira AntiVirus
TR/Crypt.XPACK.Gen
7.11.167.102

avast!
Win32:InstallMate-CJ [PUP]
2014.9-140816

AVG
Adware Agent.E
2015.0.3380

Baidu Antivirus
Trojan.Win32.InstallRex
4.0.3.14711

Bkav FE
HW32.CDB
1.3.0.4959

Clam AntiVirus
Win.Trojan.8095309
0.98/19283

Comodo Security
Application.Win32.Bundledz.C
19193

Dr.Web
Adware.Downware.97
9.0.1.0228

ESET NOD32
Win32/InstalleRex.C potentially unwanted application
8.7.0.302.0

IKARUS anti.virus
AdWare.Allpremiumsoft
t3scan.1.7.5.0

McAfee
Trojan.Artemis!D222DDE6DA68
5600.7036

Panda Antivirus
PUP/TSUploader
14.08.16.09

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.8.16.21

Rising Antivirus
PE:Trojan.Dropper!6.F48
23.00.65.14814

Sophos
PUA.InstallRex
54

SUPERAntiSpyware
Trojan.Agent/Gen-Installer
10417

Trend Micro House Call
HV_INSTALLEREX_CA08018C.TOMC
7.2.228

VIPRE Antivirus
Threat.4753027
32210

File size:
659 KB (674,816 bytes)

Product version:
1.0.8.4

Copyright:
Copyright © 2013 Aviny

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\aviny-prayer-times.exe

File PE Metadata
Compilation timestamp:
11/18/2011 8:37:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:OI3D4zYuRXVEjBfacro8CKmO821S8Z5XxM6ods/gbVBH5vEJCm7ELtsvPjl:puRXWjBvr1Sc5XnohbVTEJCGYuvPj

Entry address:
0x1513

Entry point:
55, 8B, EC, 81, EC, 38, 0B, 00, 00, 53, 56, 57, 8D, 85, E0, FE, FF, FF, 50, C7, 85, E0, FE, FF, FF, 14, 01, 00, 00, FF, 15, 74, 30, 40, 00, 85, C0, 74, 11, 33, C0, 83, BD, F0, FE, FF, FF, 01, 0F, 94, C0, A3, 00, 40, 40, 00, 33, F6, 66, 89, B5, C8, F4, FF, FF, 89, 75, F4, 89, 75, FC, FF, 15, 70, 30, 40, 00, A3, 08, 40, 40, 00, FF, 15, 6C, 30, 40, 00, 89, 45, F8, 68, 04, 01, 00, 00, 8D, 85, D8, FC, FF, FF, 50, 56, FF, 15, 68, 30, 40, 00, 85, C0, 75, 22, FF, 15, 64, 30, 40, 00, 50, 68, D0, 33, 40, 00, E8, EA...
 
[+]

Entropy:
7.9875

Developed / compiled with:
Microsoft Visual C++

Code size:
8 KB (8,192 bytes)

The file aviny-prayer-times.exe has been seen being distributed by the following URL.

Remove aviny-prayer-times.exe - Powered by Reason Core Security