download flight simulator x deluxe completo.exe

STARGLOBE LLC

The application download flight simulator x deluxe completo.exe, “Download da Internet” by STARGLOBE has been detected as a potentially unwanted program by 23 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from www.getld.space.
Publisher:
9eUZMMe8wOhPXkBAut  (signed by STARGLOBE LLC)

Description:
Download da Internet

Version:
9.5.3.4

MD5:
f2f13764bcd1a54ad33c1e0a0c5f0a6a

SHA-1:
8889e42bb8869a6e1c9939fca59c86c4c6a9d3de

SHA-256:
eaceff3dc4217322694863749b1c68f5e2116d55c80c2fb0841a0ff53bc627dd

Scanner detections:
23 / 68

Status:
Potentially unwanted

Analysis date:
5/17/2024 2:12:53 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Adload.G
5629308

AhnLab V3 Security
Adware/Win32.Adload
2015.06.03

Avira AntiVirus
TR/Dldr.Adload.dmouj
8.3.1.6

Arcabit
Adware.Adload.G
1.0.0.425

avast!
Rootkit-gen [Rtk]
150602-1

AVG
Downloader.NSIS
2014.0.4311

Baidu Antivirus
PUA.Win32.Adload
4.0.3.1563

Bitdefender
Adware.Adload.G
1.0.20.770

Comodo Security
TrojWare.Win32.TrojanDownloader.Adload.AGGL
22316

Emsisoft Anti-Malware
Adware.Adload
15.06.03

ESET NOD32
NSIS/TrojanDownloader.Adload.AM trojan
7.0.302.0

Fortinet FortiGate
Adware/AdloadAM
6/3/2015

F-Prot
W32/AdLoad.AZ.gen
v6.4.7.1.166

F-Secure
Adware.Adload.G
11.2015-03-06_4

G Data
Adware.Adload
15.6.25

K7 AntiVirus
Unwanted-Program
13.204.16117

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
14.0.0.1945

MicroWorld eScan
Adware.Adload.G
16.0.0.462

Norman
Adware.Adload.G
02.06.2015 14:23:46

nProtect
Adware.Adload.G
15.06.02.01

Sophos
PUA 'AdLoad' (of type Adware)
5.15

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

VIPRE Antivirus
Threat.4785227
40786

File size:
69.4 KB (71,064 bytes)

Copyright:
9eUZMMe8wOhPXkBAutWAE

Trademarks:
9eUZMMe8wOhPXk

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\download flight simulator x deluxe completo.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
4/2/2015 12:48:38 PM

Valid to:
4/2/2016 12:48:38 PM

Subject:
CN=STARGLOBE LLC, O=STARGLOBE LLC, L=Lewes, S=Delaware, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
430C6F7CC2E34DBF

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:uQpQ5EP0ijnRTXJv5rhzH8TvpbasF+VNX:uQIURTXJv5mTpbaCQX

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file download flight simulator x deluxe completo.exe has been seen being distributed by the following URL.