downloader_2.exe

StringEncrypt

A4 TOV

The application downloader_2.exe by A4 TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
PELock Software  (signed by A4 TOV)

Product:
StringEncrypt

Version:
1.0.0.0

MD5:
4b92590355203ff336a60455ac935a87

SHA-1:
b0ab3885c0ff0e306934f498dc37252f0899d4b4

SHA-256:
8965ce004876e60f6721ae425bcbef0a7f001e808fa4e807ccda87d8be18c9d6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/12/2024 2:44:29 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize (M)
17.3.12.20

File size:
1.5 MB (1,584,096 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Bartosz Wójcik 2013

Original file name:
StringEncrypt.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\downloader_2.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/17/2015 2:00:00 AM

Valid to:
9/17/2016 1:59:59 AM

Subject:
CN=A4 TOV, O=A4 TOV, STREET=Bud. 29 vul.Shchorsa, L=Kiev, S=Kiev, PostalCode=01010, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
27FB5DEC4CCFD4F3CF69A6B639C6AD4B

File PE Metadata
Compilation timestamp:
9/30/2015 9:32:44 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x1F191B

Entry point:
68, 40, A7, 51, 03, E8, 54, DF, FF, FF, 00, 00, 00, 47, 65, 74, 41, 43, 50, 00, 06, 4E, FA, 38, 35, 9B, DB, FB, 29, AF, 92, E2, 57, B7, AE, C4, 3F, 4D, 6D, EF, 0F, ED, BD, FC, 3C, 39, 4D, 10, 42, 02, 42, 93, B1, 64, 71, 9F, CD, 32, FA, 6B, C2, 81, F0, 57, D8, AD, DF, BF, 89, 91, AB, 79, 4D, 18, 91, 87, B2, AB, A9, 4E, 62, 3C, F8, 04, 29, 37, AE, FE, 7D, BB, 20, FE, 9E, 80, F6, A0, EF, 61, E1, EB, B3, 81, D0, AE, F7, D1, EB, 1F, 66, 67, 17, 39, E7, AF, 44, 69, 6E, 4E, 95, CA, 80, 77, 84, F9, D5, 23, B2, CB...
 
[+]

Code size:
1.5 MB (1,562,112 bytes)

Remove downloader_2.exe - Powered by Reason Core Security