cp-i9iadzmqf7dhckn9vyvkl3qfszwcgmb2asoilvpslmip9rnbi0khk_cpmnngv20bx5qbwze81hqawbpovuwrvyzw-fwnxndcb

The file cp-i9iadzmqf7dhckn9vyvkl3qfszwcgmb2asoilvpslmip9rnbi0khk_cpmnngv20bx5qbwze81hqawbpovuwrvyzw-fwnxndcb has been detected as a potentially unwanted program by 27 anti-malware scanners.
MD5:
cde786db2263efa1086ab044eaae4706

SHA-1:
5afe8f40da38c86c8ea67ab93c5be34899540c8a

SHA-256:
e8e95fd154c7fcc9a66f0d3b6a74c60678d6b1cf6a09329dd8f88a8681af2ebd

Scanner detections:
27 / 68

Status:
Potentially unwanted

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Analysis date:
4/26/2024 4:31:11 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.139785
6286450

AhnLab V3 Security
PUP/Win32.DomaIQ
2015.03.31

avast!
DomaIQ-CC [PUP]
150319-1

AVG
Adware DomaIQ.BB
2014.0.4311

Bitdefender
Gen:Variant.Adware.Graftor.139785
1.0.20.445

Clam AntiVirus
Win.Adware.Domaiq-35
0.98/21511

Comodo Security
Application.Win32.DomaIQ.PUQ
21595

Dr.Web
Trojan.DownLoader9.45575
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.139785
9.0.0.4799

ESET NOD32
Win32/DomaIQ.BA potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Lollipop
3/30/2015

F-Prot
W32/A-be0dae6d
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Graftor
5.13.68

G Data
Gen:Variant.Adware.Graftor.139785
15.3.25

herdProtect (fuzzy)
2015.7.4.21

IKARUS anti.virus
PUA.DomaIQ
t3scan.1.8.9.0

Kaspersky
not-a-virus:AdWare.Win32.Lollipop
15.0.0.543

Malwarebytes
PUP.Optional.DomalQ
v2015.03.30.10

MicroWorld eScan
Gen:Variant.Adware.Graftor.139785
16.0.0.267

NANO AntiVirus
Riskware.Win32.Lollipop.cvvfxj
0.30.8.659

Norman
Gen:Variant.Adware.Graftor.139785
03.12.2014 13:20:04

nProtect
Trojan-Clicker/W32.Lollipop.380832
15.03.30.01

Panda Antivirus
Trj/Genetic.gen
15.03.30.10

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.30.22

Sophos
DomainIQ pay-per install
4.98

Vba32 AntiVirus
BScope.Downware.DomaIQ
3.12.26.3

Zillya! Antivirus
Adware.DomaIQ.Win32.233
2.0.0.2122

File size:
371.9 KB (380,832 bytes)

Common path:
C:\users\{user}\downloads\cp-i9iadzmqf7dhckn9vyvkl3qfszwcgmb2asoilvpslmip9rnbi0khk_cpmnngv20bx5qbwze81hqawbpovuwrvyzw-fwnxndcbay0wwl1mke4_g4mtlw5hakgnxekq

File PE Metadata
Compilation timestamp:
3/10/2014 7:25:44 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:eu9LQqwcT8KcLUCYVkP3LIV1sA7crKuZfMrf5g6CEK:ewRwcTLcLAVkPb+1sAVofGq6JK

Entry address:
0x326B

Entry point:
E8, 51, 44, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B...
 
[+]

Entropy:
6.4488

Code size:
58 KB (59,392 bytes)