download the rolling stones - schoolboy blues & brown sugar feat. eric clapton 320kbps # nank

Stepan Rybin

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The file download the rolling stones - schoolboy blues & brown sugar feat. eric clapton 320kbps # nank by Stepan Rybin has been detected as adware by 28 anti-malware scanners. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Stepan Rybin  (signed and verified)

MD5:
441fcce3233135121345c73d3887b556

SHA-1:
993a141100f5237181e362bddda26da3b8a422f5

SHA-256:
dfabcbddbb9fa3ab3d4a222ec5e0cd1c59e6512a6bb11543830ae215e717d6e0

Scanner detections:
28 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
5/2/2024 3:00:51 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.MPLug.HH
6312761

Agnitum Outpost
PUA.MultiPlug
7.1.1

AhnLab V3 Security
PUP/Win32.MultiPlug
2015.03.28

Avira AntiVirus
PUA/MultiPlug.11245
3.6.1.96

avast!
Win32:Adware-gen [Adw]
150319-1

AVG
Adware Generic_r.ABT
2014.0.4311

Bitdefender
Adware.MPLug.HH
1.0.20.435

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.MultiPlug.YTRA
21564

Dr.Web
Trojan.Crossrider1.22656
9.0.1.05190

Emsisoft Anti-Malware
Adware.MPLug.HH
9.0.0.4799

ESET NOD32
Win32/Adware.MultiPlug.FV application
7.0.302.0

Fortinet FortiGate
Riskware/MultiPlug
3/28/2015

F-Secure
Adware.MPLug.HH
5.13.68

G Data
Adware.MPLug.HH
15.3.25

IKARUS anti.virus
AdWare.MultiPlug
t3scan.1.8.9.0

K7 AntiVirus
Unwanted-Program
13.202.15408

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
14.0.0.2280

Malwarebytes
PUP.Optional.Bundler
v2015.03.28.02

McAfee
Program.MultiPlug-FWZ
16.8.708.2

MicroWorld eScan
Adware.MPLug.HH
16.0.0.261

NANO AntiVirus
Riskware.Win32.MultiPlug.dplmsr
0.30.8.659

nProtect
Adware.MPLug.HH
15.03.27.01

Reason Heuristics
PUP.WebPick
15.3.28.2

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15326

Sophos
MultiPlug
4.98

Vba32 AntiVirus
suspected of Heur.Malware-Cryptor.Multiplug
3.12.26.3

File size:
471.2 KB (482,504 bytes)

Common path:
C:\users\{user}\downloads\download the rolling stones - schoolboy blues & brown sugar feat. eric clapton 320kbps # nanker phelge torrent -%.exe.o5ib8s6.partial

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
6/27/2014 11:37:40 AM

Valid to:
6/27/2015 11:37:40 AM

Subject:
E=rybin.step@yandex.ru, CN=Stepan Rybin, O=Stepan Rybin, C=UA

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
47154C2151E9EB8DFA42C2C9E45BFC6C

File PE Metadata
Compilation timestamp:
1/29/2013 3:53:21 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:Hx/Crx6VRd9D5Y9Xz2S3ilOLa9DgYf2B7z:06ndbS34KBf

Entry address:
0x4517B

Entry point:
E8, CF, 1F, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, C0, 02, 45, 00, E8, DF, 24, 00, 00, E8, 9C, 21, 00, 00, 0F, B7, F0, 6A, 02, E8, 62, 1F, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 28, 02, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
297 KB (304,128 bytes)