cliquez ici pour votre fi_10924_i129717953_il345.exe

doPDF 8

AITI Strim CONSULTING, TOV

The application cliquez ici pour votre fi_10924_i129717953_il345.exe by AITI Strim CONSULTING, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Softland  (signed by AITI Strim CONSULTING, TOV)

Product:
doPDF 8

Version:
8.5.937

MD5:
9b55ebd9de2a2f9080441764b536cf30

SHA-1:
211ca7e813e7f28b22c9dd5a121361de436551a6

SHA-256:
5272b2f3416694d79e95ad27bd5cebf93f096781577fb71dd1579fc0ea823548

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 4:26:28 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize.AITIStri (M)
16.6.16.13

File size:
2.4 MB (2,544,080 bytes)

Product version:
8.5.937

Copyright:
Copyright (c) Softland. All rights reserved.

Original file name:
novapdf.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\cliquez ici pour votre fi_10924_i129717953_il345.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/10/2016 9:00:00 PM

Valid to:
1/10/2017 8:59:59 PM

Subject:
CN="AITI Strim CONSULTING, TOV", OU=IT, O="AITI Strim CONSULTING, TOV", STREET="Bud. 53-55, vul.Pochainynska", L=Kyyiv, S=Kyyiv, PostalCode=04080, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5A7A1CB365BD8EA3567456D3B8166630

File PE Metadata
Compilation timestamp:
1/25/2016 1:52:52 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:uoKvxsTvU17ufPBVLY3XTYahiAJwhCPoU/q3F+1psEL:NK9OPDLY3jYln+13L

Entry address:
0x319CB7

Entry point:
68, 73, 3B, 71, 01, E8, 72, 77, F9, FF, 97, EE, 71, 7D, 22, C9, 27, DF, 11, E6, 6A, 76, 98, AA, AA, C0, 20, 46, F5, 66, F7, C7, 08, 5C, F8, 84, C9, 0F, 85, AF, 14, 1A, 00, 5E, 5B, 33, C0, 66, BF, C1, 35, 5F, E9, 9E, E6, FF, FF, 83, E1, FE, F5, 83, C1, 0B, E9, 82, 5E, 05, 00, F7, D0, E9, AB, 27, 00, 00, AD, F4, CA, 3A, 59, D1, 9C, CA, 3A, 2E, 88, 90, CA, 3A, 4F, F9, 92, CA, 3A, 9D, 61, 34, CD, 3A, 36, D6, CD, 34, C5, 05, 4D, D9, 32, C5, 40, E4, DF, CA, 3A, D8, B0, 8A, CD, 3A, AB, 05, 25, 34, C5, AD, 0B, 39...
 
[+]

Code size:
2.1 MB (2,211,328 bytes)