gamenutt-setup.exe

Download Admin

This is the Tightrope WebInstall which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application gamenutt-setup.exe by Download Admin has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the Tightrope WebInstall installer. The file has been seen being downloaded from files4.mirror1.info and multiple other hosts.
Publisher:
Download Admin  (signed and verified)

MD5:
667ece8dded85552880f7b690e1ac485

SHA-1:
c2f974a1dc3ce3c9fd1ed5215c95613ef5ec0faa

SHA-256:
ac12e9b2f9dfb7870bfb92be30507f6d1e2e2ebac6d1dfee4d9a809130fc7c44

Scanner detections:
11 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/24/2024 1:20:51 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen9
7.11.159.230

Clam AntiVirus
Win.Adware.Agent-6650
0.98/19073

Dr.Web
Adware.Downware.557
9.0.1.05190

ESET NOD32
Win32/DownloadAdmin.G potentially unwanted application
7.0.302.0

F-Secure
Adware:W32/WebInstallBundle
11.2014-10-07_5

Malwarebytes
PUP.Optional.DownloadAdmin
v2014.07.10.12

NANO AntiVirus
Riskware.Win32.Downware.crgjbr
0.28.0.60698

Reason Heuristics
PUP.Installer.DownloadAdmin.O
14.8.7.20

Sophos
Download Admin
4.98

Trend Micro House Call
HV_DOWNLOADADMIN_CG094603.RDXN
7.2.191

VIPRE Antivirus
Threat.4783369
31088

File size:
717.4 KB (734,592 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tightrope WebInstall (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\gamenutt-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/2/2010 8:00:00 PM

Valid to:
5/29/2013 7:59:59 PM

Subject:
CN=Download Admin, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Download Admin, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
29529B0D185F8525A92A866D4A38DA3A

File PE Metadata
Compilation timestamp:
6/22/2012 2:07:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:RxpJXtH88KxYxD24EcTL/WC4Vm8xJFppf70l1fpHz97o:jppV88fD2M34VmkJFpd7qH5o

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
7.3815

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file gamenutt-setup.exe has been seen being distributed by the following 3 URLs.

Remove gamenutt-setup.exe - Powered by Reason Core Security