corel draw x7 serial numb_10924_i129768828_il345.exe

AITI Strim CONSULTING, TOV

The application corel draw x7 serial numb_10924_i129768828_il345.exe by AITI Strim CONSULTING, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
AITI Strim CONSULTING, TOV  (signed and verified)

MD5:
856aa41feefacbef1c998f022ec76f57

SHA-1:
c9735d58ce7402303dff7695ea0d04c9323413df

SHA-256:
fe2ea59c62b2b754487667a075a27fe11758bcdf625a222ed0e8d90fef8b4fdb

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 4:03:05 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize.AITIStri (M)
16.7.5.21

File size:
2 MB (2,062,608 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\corel draw\corel draw x7 serial numb_10924_i129768828_il345.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/10/2016 6:00:00 PM

Valid to:
1/10/2017 5:59:59 PM

Subject:
CN="AITI Strim CONSULTING, TOV", OU=IT, O="AITI Strim CONSULTING, TOV", STREET="Bud. 53-55, vul.Pochainynska", L=Kyyiv, S=Kyyiv, PostalCode=04080, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5A7A1CB365BD8EA3567456D3B8166630

File PE Metadata
Compilation timestamp:
1/25/2016 3:52:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:HmjTmHIvDqLv7isaCKG2plDYK/1v9vXgK:Gv7DyvGsGFF1NT

Entry address:
0x2E6AB3

Entry point:
68, 89, 00, 25, 7E, E8, 10, EE, F9, FF, 6B, 83, ED, 3A, 98, C5, 17, 51, 9B, 17, CA, 19, FF, A8, EB, B6, C0, CB, FA, A2, FF, 81, 78, C8, 61, BC, 28, 90, 4B, B9, 64, D2, 1B, BC, 31, EC, 70, 59, A1, 19, C4, 1B, 9B, 29, 29, F4, F3, 11, DF, C7, 9A, 7E, 50, C8, 2C, F1, 07, A5, 42, 02, D8, E7, B6, 21, F1, A2, A3, 85, 8F, 45, 49, 80, 3D, A8, 17, 0F, 46, 30, 0B, 26, 07, A8, 0D, B8, 15, BC, E1, 23, 86, D4, 86, FA, FE, B9, C4, 1A, 24, 4F, 5B, 69, E3, F5, F3, CA, 6B, 71, 44, 99, 3F, A0, C6, DB, 22, 99, 47, 7B, A6, D2...
 
[+]

Entropy:
7.9864  (probably packed)

Code size:
2 MB (2,051,072 bytes)