drakebacktobackvbrmixjoint__15022_i1603872874_il1581775.exe.rar

The file drakebacktobackvbrmixjoint__15022_i1603872874_il1581775.exe.rar has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from a.kat.cr.
MD5:
1e0fd68f5ae858591f27871bf3da9770

SHA-1:
23478a565afc86a0164100e61a2f16c70a51aaed

SHA-256:
c2615ab04cad2158066b4db67444f37bf05eb7d4b17e664a7775c89e1fb62f69

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/16/2024 6:07:20 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Amonetize (M)
16.7.22.18

File size:
611.1 KB (625,736 bytes)

Common path:
C:\users\{user}\downloads\drakebacktobackvbrmixjoint__15022_i1603872874_il1581775.exe.rar

The file drakebacktobackvbrmixjoint__15022_i1603872874_il1581775.exe.rar has been seen being distributed by the following URL.