download pro evolution soccer 2013 ptbr para ps2.zip.exe

MIDIA TECHNOLOGIES LLC

The application download pro evolution soccer 2013 ptbr para ps2.zip.exe by MIDIA TECHNOLOGIES has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the Midia Downloader installer. The file has been seen being downloaded from www.alamaya.me.
Publisher:
MIDIA TECHNOLOGIES LLC  (signed and verified)

MD5:
4ab2ecc2561e5b65611691317f1df071

SHA-1:
c335ffdff6fbd5f9f278bbce408f6e9d51717e16

SHA-256:
c0cee131b5e79a2924e62b1b929f81e4c4b380a4e672b9c1184d2f3b3e718eb6

Scanner detections:
11 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/16/2024 10:24:53 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Rootkit-gen [Rtk]
140813-1

Baidu Antivirus
Trojan.Win32.Generic
4.0.3.1497

ESET NOD32
NSIS/TrojanDownloader.Agent.NQD
8.10380

Fortinet FortiGate
W32/Adload.S!tr.dldr
9/7/2014

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
14.0.0.3285

Malwarebytes
PUP.Optional.Midia
v2014.09.07.11

Norman
Downloader
11.20140907

Reason Heuristics
PUP.MIDIATECHNOLOGIES.t
14.9.7.20

SUPERAntiSpyware
Trojan.Agent/Gen-FakeAlert
10373

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.4150696
32210

File size:
56.5 KB (57,880 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Midia Downloader (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\download pro evolution soccer 2013 ptbr para ps2.zip.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
9/4/2014 12:26:04 AM

Valid to:
4/11/2015 3:45:06 PM

Subject:
CN=MIDIA TECHNOLOGIES LLC, O=MIDIA TECHNOLOGIES LLC, L=Lewes, S=Delaware, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
042D801BEEE617

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:XpgpHzb9dZVX9fHMvG0D3XJbC6K1KYqmlYUZ0Lr:ZgXdZt9P6D3XJbC6zYqmlYUC

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file download pro evolution soccer 2013 ptbr para ps2.zip.exe has been seen being distributed by the following URL.