getitfree.exe

Get It Free

Amazing Apps

This is the installer application for a 50onRed advertising supported software package (displays ads in the browser and may hijack the home and search pages of the web browser). The application getitfree.exe, “Get It Free Installer” by Amazing Apps has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
Publisher:
215 Apps  (signed by Amazing Apps)

Product:
Get It Free

Description:
Get It Free Installer

Version:
1.17.149.149

MD5:
105b6af96e694c40b16592f7266f112b

SHA-1:
677437ee2cb274b661962c8013b154851460500d

SHA-256:
b541cfd80aa5b6f0332d11e88d44b94e8c5937da3645d7247b7463882f70f4fd

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
4/25/2024 8:47:07 PM UTC  (today)

Scan engine
Detection
Engine version

Bitdefender
Gen:Variant.Adware.VidSaver.1
1.0.20.190

Comodo Security
ApplicUnwnt
17277

Dr.Web
Adware.GamePlayLabs.31
9.0.1.038

Emsisoft Anti-Malware
Gen:Variant.Adware.VidSaver
8.15.02.07.12

ESET NOD32
Win32/Toolbar.CrossRider (variant)
9.9054

Fortinet FortiGate
Adware/Fam.NB
2/7/2015

F-Secure
Gen:Variant.Adware.VidSaver.1
11.2015-07-02_7

G Data
Gen:Variant.Adware.VidSaver
15.2.22

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.2.29

McAfee
RDN/Generic PUP.x!bb3
5600.6861

MicroWorld eScan
Gen:Variant.Adware.VidSaver.1
16.0.0.114

Quick Heal
Adware.Crossid (Not a Virus)
2.15.12.00

Reason Heuristics
PUP.Installer.50OnRed
15.2.7.12

Trend Micro House Call
TROJ_GEN.R0CBC0OHG13
7.2.38

Trend Micro
TROJ_GEN.R0CBC0OHG13
10.465.07

VIPRE Antivirus
GamePlayLabs
23398

File size:
1.8 MB (1,860,144 bytes)

Copyright:
Copyright 215 Apps

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\getitfree.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/30/2012 8:00:00 PM

Valid to:
5/1/2013 7:59:59 PM

Subject:
CN=Amazing Apps, O=Amazing Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2E307885017928B61D4F2CEF5EB10A05

File PE Metadata
Compilation timestamp:
1/5/2010 7:09:32 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
24576:KTnGXu3vcV2KSeq6HOoAqRcId0U8TBOefpGaz8kyuKtTOeWcSaF394/VxlDsxE7s:qPI2Ky6cIdZ8Tto4yYefdWrpctvN+0mU

Entry address:
0x4044

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, E8, 97, 52, 00, 00, C7, 04, 24, 01, 80, 00, 00, E8, 43, 4F, 00, 00, 56, C7, 04, 24, 00, 00, 00, 00, E8, A6, 52, 00, 00, A3, 88, 5C, 42, 00, 53, C7, 04, 24, 08, 00, 00, 00, E8, 26, 32, 00, 00, A3, 38, 5D, 42, 00, 8D, 85, 84, FE, FF, FF, 51, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A4, B2, 40, 00, E8, D0, 51, 00, 00, 83, EC, 14, C7, 44, 24, 04, A5, B2, 40, 00, C7, 04, 24, 68, 5D...
 
[+]

Entropy:
7.9889  (probably packed)

Code size:
33 KB (33,792 bytes)

The file getitfree.exe has been seen being distributed by the following URL.

Remove getitfree.exe - Powered by Reason Core Security