c66944ab5e2fe18d788cf92c227d4d5009c2367a

RF Software

According to Microsoft Security Essentials, the software includes a bundle of the DealPly adware which is installed on a user's PC during setup using the InstallCore platform. The file has been seen being downloaded from www.filefree.me.
Publisher:
RF Software  (signed and verified)

Version:
1.0.4917.35105

MD5:
f02384dbfa49834a04792987165d7c21

SHA-1:
233fb35d72a3643ee476034a9ef24a793ab59c06

SHA-256:
93899bd5e84f1d700290375008fce5ec3add64cea670e8eb7c6a2e9748198365

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/19/2024 9:02:05 PM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
SoftwareBundler
t3scan.2.0.127

Microsoft Security Essentials
1.163.1557.0

Panda Antivirus
Trj/OCJ.D
14.11.30.05

File size:
320.4 KB (328,040 bytes)

Product version:
1.0.4917.35105

Original file name:
SampleWebDownloader.exe

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\apple computer\mobilesync\backup\584a7764e4d17642dbe6fd36e74a2a9b938f44dc\c66944ab5e2fe18d788cf92c227d4d5009c2367a

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
5/27/2013 6:46:49 AM

Valid to:
5/27/2014 6:46:49 AM

Subject:
E=rafick_mat@msn.com, CN="Open Source Developer, Rafick FERNANDES", O=RF Software, C=BR

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
04FF243AB0C89789C6527B1B993060D7

File PE Metadata
Compilation timestamp:
6/18/2013 2:31:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:yBroprX4ABDLwT4gbpuguNNqBSGHByBrBnebRBwiB+G50tqpyeB++xU:yBirX3BDLdgbaiBSGHByBrBneFBV+G5O

Entry address:
0x4E32E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
305 KB (312,320 bytes)

The file c66944ab5e2fe18d788cf92c227d4d5009c2367a has been seen being distributed by the following URL.

http://www.filefree.me/ids/.../?title=José do Egito Capítulo 22Completa

Scan c66944ab5e2fe18d788cf92c227d4d5009c2367a - Powered by Reason Core Security