emulador gba.exe

Get your downloads

Maxiget Limited

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application emulador gba.exe by Maxiget Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the New IT Desktop Setup installer. The file has been seen being downloaded from ds312.maxiget.com.
Publisher:
Company #1  (signed by Maxiget Limited)

Product:
Get your downloads

Version:
3, 1, 16, 0

MD5:
e047087c69e2f209331cfbb808365b5a

SHA-1:
12888698cede5a9e01628553b5de43771aefbb43

SHA-256:
566d9aad471a6a372a92d17c8003dbddcb1774f228e8301ed2eef9e837464259

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This is a modified installer version of the software and bundles additional offers including adware.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/23/2024 10:09:18 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.New IT Limited (M)
16.8.10.13

File size:
544.4 KB (557,448 bytes)

Product version:
3, 1, 16, 0

Copyright:
Copyright (C) 2013

Trademarks:
TM(c)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
New IT Desktop Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\emulador gba.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
8/15/2013 3:41:32 AM

Valid to:
8/15/2016 3:41:32 AM

Subject:
CN=Maxiget Limited, O=Maxiget Limited, L=Limassol, S=Cyprus, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
045BA815265145

File PE Metadata
Compilation timestamp:
11/29/2013 2:35:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:YthVzPkmv/dqafYz8SB5ry3wQw/gaBEsemBps1fYJDN+TjZ5XWWnA:cTmry3UoaBEseK0Qj+TjZ5

Entry address:
0x3BBF6

Entry point:
E8, 3D, 30, 01, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 4D, 08, EB, 07, 49, 80, 38, 00, 74, 06, 40, 85, C9, 75, F5, 49, 8B, 45, 08, 2B, C1, 48, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 14, A1, D4, 6C, 47, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 57, 8B, F1, 39, 1D, EC, 84, 47, 00, 75, 38, 53, 53, 33, FF, 47, 57, 68, 14, B9, 46, 00, 68, 00, 01, 00, 00, 53, FF, 15, 8C, 81, 46, 00, 85, C0, 74, 08, 89, 3D, EC, 84, 47, 00, EB, 15, FF, 15, 70, 80, 46, 00, 83, F8, 78, 75, 0A, C7, 05, EC, 84, 47, 00, 02, 00, 00...
 
[+]

Code size:
409.5 KB (419,328 bytes)

The file emulador gba.exe has been seen being distributed by the following URL.

Remove emulador gba.exe - Powered by Reason Core Security