fatalpuzzle.exe

Absolutist

The application fatalpuzzle.exe, “Fatal Puzzle Setup ” by Absolutist has been detected as a potentially unwanted program by 11 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from fs3.absolutist.com.
Publisher:
Absolutist Ltd.   (signed by Absolutist)

Description:
Fatal Puzzle Setup

MD5:
ca36b47212cc6b106bb7c217985a508f

SHA-1:
59a314763d5ca921ac58bc1efa9fbd03aaf7a599

SHA-256:
1542e64d8844cae227303278f33865a313bfbd0712c635206820efa71500158e

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Analysis date:
5/21/2024 12:58:19 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
W32.Adware.Conduit!c
2.1.4+

Bkav FE
W32.HfsAdware
1.3.0.8455

Dr.Web
Adware.Conduit.37
9.0.1.0301

ESET NOD32
Win32/Toolbar.Conduit.B potentially unwanted (variant)
10.14314

F-Prot
W32/Conduit.A.gen
v6.4.7.1.166

G Data
Win32.Adware.Conduit
16.10.25

McAfee
Artemis!CA36B47212CC
5600.6234

NANO AntiVirus
Riskware.Win32.Conduit.duufey
1.0.44.12357

Quick Heal
PUA.Conduitltd1.Gen
10.16.14.00

Reason Heuristics
Adware.Conduit (M)
16.10.27.6

ViRobot
Adware.Conduit.2320768[h]
2014.3.20.0

File size:
2.2 MB (2,320,768 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
English (United States)

Common path:
C:\users\{user}\downloads\fatalpuzzle.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/2/2014 2:00:00 AM

Valid to:
7/3/2015 1:59:59 AM

Subject:
CN=Absolutist, O=Absolutist, STREET=XXII partsezda 53, L=Dnepropetrovsk, S=Dnepropetrovskaya, PostalCode=49029, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A4F671DF7E50A18FF867F72E9504EA98

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:n2RacUM20bWuFeSXXtYg4Aha0tlBHmumA9Sw:2RaYNF6Aha0t7HDsw

Entry address:
0x991C

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, AA, 97, FF, FF, E8, B1, A9, FF, FF, E8, DC, CB, FF, FF, E8, 63, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, C6, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 7C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D4, CD, 40, 00, E8, 5B, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D4, CD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.9956

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36.5 KB (37,376 bytes)

The file fatalpuzzle.exe has been seen being distributed by the following URL.

http://fs3.absolutist.com/.../fatalpuzzle.exe

Remove fatalpuzzle.exe - Powered by Reason Core Security