filmboyka3truefrenchbrrip2015_downloader-n4blveydt.exe.zip

The file filmboyka3truefrenchbrrip2015_downloader-n4blveydt.exe.zip has been detected as a potentially unwanted program by 20 anti-malware scanners. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from sub.yorkshatb.com.
MD5:
52de52aa1a69c4f7a1e46b4b27cf6d80

SHA-1:
f33b91609bf5747860cb613d75003e489c98e150

SHA-256:
9a976e497bee647dcb11530ea21a39b077ad6fd1b8e13d8a2113342b9e543da4

Scanner detections:
20 / 68

Status:
Potentially unwanted

Explanation:
Uses the Somoto 'BetterInstaller' to bundle additional (unwanted) software during install without adequate consent.

Analysis date:
4/25/2024 3:50:52 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Somoto.AH
536

Avira AntiVirus
PUA/Somoto.Gen2
8.3.1.6

Arcabit
Application.Bundler.Somoto.AH
1.0.0.425

avast!
NSIS:Adware-ZI [PUP]
2014.9-150818

AVG
Downloader
2016.0.3014

Bitdefender
Application.Bundler.Somoto.AH
1.0.20.1150

Clam AntiVirus
Win.Adware.Somoto
0.98/20801

Dr.Web
Threat.Undefined
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.Somoto.AH
10.0.0.5366

ESET NOD32
Win32/Somoto.G potentially unwanted application
7.0.302.0

F-Prot
W32/SomotoBetterInstaller.F.
v6.4.7.1.166

F-Secure
Application.Bundler.Somoto
11.2015-18-08_3

K7 AntiVirus
Trojan
13.2016920

Kaspersky
not-a-virus:HEUR:Downloader.NSIS.Somoto
14.0.0.1563

MicroWorld eScan
Application.Bundler.Somoto.AH
16.0.0.690

NANO AntiVirus
Trojan.Win32.Agent.dtledk
0.30.24.3079

Panda Antivirus
PUP/Somoto
15.08.18.10

Trend Micro House Call
ADW_TOMOS.SMN
7.2.230

Trend Micro
ADW_TOMOS.SMN
10.465.18

VIPRE Antivirus
Trojan.Win32.Generic
42988

File size:
379.4 KB (388,536 bytes)

Common path:
C:\users\{user}\downloads\filmboyka3truefrenchbrrip2015_downloader-n4blveydt.exe.zip

The file filmboyka3truefrenchbrrip2015_downloader-n4blveydt.exe.zip has been seen being distributed by the following URL.