cheatengine64_downloader-q8z9md8zw.exe

Somoto Israel Ltd.

This is the Somoto BetterInstaller, an installer that bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application cheatengine64_downloader-q8z9md8zw.exe by Somoto Israel has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Somoto BetterInstaller installer. The file has been seen being downloaded from www.cheatengine.org.
Publisher:
Somoto Israel Ltd.  (signed and verified)

MD5:
9fc74ed5bac37c9448d0d95181de5cfd

SHA-1:
7e6819877dcbd934d41a35dd3351e0f00d238ca3

SHA-256:
46f2e6f85df41b03bbff43fe506e36c76ec342cd0ed483f1c163da227bb2f1bc

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/16/2024 12:01:55 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Somoto (M)
16.7.21.14

File size:
698.1 KB (714,840 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Somoto BetterInstaller

Common path:
C:\users\{user}\downloads\cheatengine64_downloader-q8z9md8zw.exe

Digital Signature
Authority:
Somoto Israel Ltd.

Valid from:
1/28/2015 3:45:34 PM

Valid to:
1/28/2016 4:05:34 PM

Subject:
CN=Somoto Israel Ltd., OU="", O=Somoto Israel Ltd., L=Tel Aviv, S=Israel, C=IL

Issuer:
CN=Somoto Israel Ltd., OU="", O=Somoto Israel Ltd., L=Tel Aviv, S=Israel, C=IL

Serial number:
66193B5EACC01CB140D8D920D06C3660

File PE Metadata
Compilation timestamp:
12/17/2010 10:14:15 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
12288:qF80ogG7SudFVoY3AoeUdcHrp0lZw5CzK3BxQOMy749W2H+2Z:qFdoy8FV/QoW20OexQK74xHnZ

Entry address:
0x380C

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, 7C, 01, 00, 00, E8, 87, 4D, 00, 00, 83, EC, 0C, 68, 01, 80, 00, 00, E8, 2A, 4A, 00, 00, 6A, 00, E8, 9B, 4D, 00, 00, 6A, 08, A3, 28, F9, 42, 00, E8, B1, 28, 00, 00, 6A, 00, 68, 60, 01, 00, 00, A3, D8, F9, 42, 00, 8D, 85, 90, FE, FF, FF, 50, 6A, 00, 68, 4C, A2, 40, 00, E8, E0, 4C, 00, 00, 83, EC, 0C, 68, 4D, A2, 40, 00, 68, 08, FA, 42, 00, E8, EF, 2A, 00, 00, 83, C4, 18, E8, E6, 49, 00, 00, 52, 52, 50, 68, 00, 80, 43, 00, E8, DA, 2A, 00, 00, 57, 6A, 00, E8, 29, 49, 00, 00, 83...
 
[+]

Entropy:
7.9571  (probably packed)

Code size:
30 KB (30,720 bytes)

The file cheatengine64_downloader-q8z9md8zw.exe has been seen being distributed by the following URL.

Remove cheatengine64_downloader-q8z9md8zw.exe - Powered by Reason Core Security