boz.mongoose.101.mac.win.exe

Get your downloads

Maxiget Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application boz.mongoose.101.mac.win.exe by Maxiget Limited has been detected as adware by 14 anti-malware scanners. The file has been seen being downloaded from ds123.maxiget.com.
Publisher:
Company #1  (signed by Maxiget Limited)

Product:
Get your downloads

Version:
3, 1, 28, 0

MD5:
c50c5286e9b7242f977c685f648ef27d

SHA-1:
1b02625d0904ee8b2b042fb283f9ddbdd335317d

SHA-256:
989733fbbe09e7a4b94a39dff06f878f258cbc9bab12abfd3a3479328d076b85

Scanner detections:
14 / 68

Status:
Adware

Explanation:
This is a modified installer version of the software and bundles additional offers including adware.

Analysis date:
4/19/2024 8:53:46 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.4Shared
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.155.180

AVG
Trojan horse Dropper.Agent.BIQP
2014.0.3972

Comodo Security
Application.Win32.Graftor.KLK
18598

ESET NOD32
Win32/4Shared.P potentially unwanted application
7.0.302.0

G Data
Win32.Trojan.TorrentNZ
14.6.24

IKARUS anti.virus
not-a-virus:Downloader.Win32.GetFaster
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.4Shared.A
v2014.06.19.08

McAfee
PUP-FIW
5600.7095

NANO AntiVirus
Trojan.Win32.Agent.ctkcbd
0.28.0.60253

Reason Heuristics
PUP.MaxigetLimited.U
14.8.7.21

Sophos
4Share Downloader
4.98

Vba32 AntiVirus
TrojanDropper.Agent
3.12.26.3

VIPRE Antivirus
Threat.4838292
29708

File size:
374.2 KB (383,216 bytes)

Product version:
3, 1, 28, 0

Copyright:
Copyright (C) 2013

Trademarks:
TM(c)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
8/15/2013 3:41:32 PM

Valid to:
8/15/2016 3:41:32 PM

Subject:
CN=Maxiget Limited, O=Maxiget Limited, L=Limassol, S=Cyprus, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
045BA815265145

File PE Metadata
Compilation timestamp:
1/18/2014 12:48:10 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:139pEoamDLQk1gn+FADNHxxFm9yIrKW8ttV5wlg:1nEVSLCiAFxxFm9yIrKWwtUg

Entry address:
0x25834

Entry point:
E8, 23, 92, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 14, A1, A0, 3A, 44, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 57, 8B, F1, 39, 1D, CC, 50, 44, 00, 75, 38, 53, 53, 33, FF, 47, 57, 68, 90, B0, 43, 00, 68, 00, 01, 00, 00, 53, FF, 15, 7C, 91, 43, 00, 85, C0, 74, 08, 89, 3D, CC, 50, 44, 00, EB, 15, FF, 15, 70, 90, 43, 00, 83, F8, 78, 75, 0A, C7, 05, CC, 50, 44, 00, 02, 00, 00, 00, 39, 5D, 14, 7E, 22, 8B, 4D, 14, 8B, 45, 10, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, 45, 14, 2B, C1...
 
[+]

Entropy:
6.8198

Code size:
223 KB (228,352 bytes)

The file boz.mongoose.101.mac.win.exe has been seen being distributed by the following URL.

Remove boz.mongoose.101.mac.win.exe - Powered by Reason Core Security