downloader_10924_i66176982_il345.exe

StringEncrypt

A4 TOV

The application downloader_10924_i66176982_il345.exe by A4 TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
PELock Software  (signed by A4 TOV)

Product:
StringEncrypt

Version:
1.0.0.0

MD5:
6a81912ad9171fdc406241a0fc63732b

SHA-1:
c0d2ac67adfea8362f3383142b423cc354827c1c

SHA-256:
074869aeb8e427698973402eb2c7cbb80bf601efab26b275bf58fe0852d755f4

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/12/2024 10:41:34 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize (M)
17.2.9.5

File size:
1.5 MB (1,578,976 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Bartosz Wójcik 2013

Original file name:
StringEncrypt.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\downloader_10924_i66176982_il345.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/17/2015 3:00:00 AM

Valid to:
9/17/2016 2:59:59 AM

Subject:
CN=A4 TOV, O=A4 TOV, STREET=Bud. 29 vul.Shchorsa, L=Kiev, S=Kiev, PostalCode=01010, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
27FB5DEC4CCFD4F3CF69A6B639C6AD4B

File PE Metadata
Compilation timestamp:
10/1/2015 7:42:44 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x1F6200

Entry point:
68, 0C, E9, 14, AE, E8, 41, 94, FF, FF, 83, CD, 90, AA, 03, B0, F0, C3, C4, 53, EE, 99, 38, 3B, 55, 03, D8, 90, AA, 93, 62, 92, 96, AA, 7A, 9A, CD, C3, C4, E9, C0, AC, 69, 55, D8, 65, 17, 03, 3B, D6, 8E, 18, 9A, AA, 8E, 9E, 4C, C7, C4, 35, 3C, 9D, 03, 3B, 4F, 5B, F5, 9A, AA, D3, 23, 58, C2, C4, 28, 13, BA, 3C, 3B, 70, CA, E6, FC, C4, 55, 0E, 68, 55, 5D, E0, 8B, 38, 3B, F3, 6E, D2, 97, AA, 2E, B6, 08, 91, AA, F6, 42, 5F, C7, C4, A9, 49, 8B, 3C, 3B, C7, 25, 91, AA, AF, 8F, 66, 91, AA, 50, 75, 97, AA, 78, 4D...
 
[+]

Code size:
1.5 MB (1,556,992 bytes)

Remove downloader_10924_i66176982_il345.exe - Powered by Reason Core Security