game+thrones+season+6_10924_i66754517_il345.exe

Système d’exploitation Microsoft Windows

A4 TOV

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application game+thrones+season+6_10924_i66754517_il345.exe, “Gadgets du Bureau Windows” by A4 TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Microsoft Corporation  (signed by A4 TOV)

Product:
Système d’exploitation Microsoft® Windows®

Description:
Gadgets du Bureau Windows

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
f05f356375a35cf699a6f202af1537c2

SHA-1:
00ed3571fbc840f17c250e3094b8263ec17e7a51

SHA-256:
4045a0a195f9bc3718a1bd200527e277f67eece6076bef7d03d87e4e9e6d9eea

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/13/2024 2:20:11 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize (M)
17.2.20.18

File size:
2.2 MB (2,291,168 bytes)

Product version:
1.0.7600.16385

Copyright:
© Microsoft Corporation. Tous droits réservés.

Original file name:
sidebar.EXE.MUI

File type:
Executable application (Win32 EXE)

Language:
French (France)

Common path:
C:\users\{user}\downloads\game+thrones+season+6_10924_i66754517_il345.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/17/2015 2:00:00 AM

Valid to:
9/17/2016 1:59:59 AM

Subject:
CN=A4 TOV, O=A4 TOV, STREET=Bud. 29 vul.Shchorsa, L=Kiev, S=Kiev, PostalCode=01010, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
27FB5DEC4CCFD4F3CF69A6B639C6AD4B

File PE Metadata
Compilation timestamp:
10/3/2015 11:12:43 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x27D928

Entry point:
68, 74, 34, F7, A0, E8, 7E, D8, FF, FF, 00, 00, 4C, 6F, 61, 64, 4C, 69, 62, 72, 61, 72, 79, 41, 00, 00, 55, 53, 45, 52, 33, 32, 2E, 64, 6C, 6C, 00, F9, FD, 00, 83, AF, B0, B6, FF, 7C, 66, 89, 7A, 01, 83, 58, FF, 41, 03, 83, 3B, 3B, F3, FE, 7C, C8, A8, 32, 05, 83, ED, 32, 53, FE, 7C, DC, AC, D2, FE, 7C, 7B, 0C, 30, 01, 83, 26, 29, 67, 01, 83, 02, CA, 11, 03, 83, 66, F9, 19, FD, 7C, 12, 15, 0E, FC, 7C, 61, 4D, 05, 83, 61, F0, AE, 45, 04, 83, C1, 50, 86, AC, 01, 83, 3E, 1D, FB, 7C, FC, 4A, 90, A5, 87, 82, FB...
 
[+]

Code size:
1.9 MB (2,022,400 bytes)