gwiezdne wojny przebudze_10924_i129867167_il345.exe

Pixillion

AITI Strim CONSULTING, TOV

The application gwiezdne wojny przebudze_10924_i129867167_il345.exe, “Pixillion Image Converter” by AITI Strim CONSULTING, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
NCH Software  (signed by AITI Strim CONSULTING, TOV)

Product:
Pixillion

Description:
Pixillion Image Converter

Version:
2.96+

MD5:
c829eb3d079e665c2fa81d936a0bed3f

SHA-1:
750397e4f9dbef3b3fee08f05f34fc647d124459

SHA-256:
a336764d32598568cdde95757912d0dcd91a1dc0065104fad6732149c81d7cfe

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 4:01:35 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize (M)
17.1.10.18

File size:
2.1 MB (2,167,424 bytes)

Product version:
2.96+

Copyright:
NCH Software

Original file name:
Pixillion.exe

File type:
Executable application (Win32 EXE)

Language:
English (Australia)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\gwiezdne wojny przebudze_10924_i129867167_il345.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/11/2016 1:00:00 AM

Valid to:
1/11/2017 12:59:59 AM

Subject:
CN="AITI Strim CONSULTING, TOV", OU=IT, O="AITI Strim CONSULTING, TOV", STREET="Bud. 53-55, vul.Pochainynska", L=Kyyiv, S=Kyyiv, PostalCode=04080, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5A7A1CB365BD8EA3567456D3B8166630

File PE Metadata
Compilation timestamp:
1/26/2016 7:02:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x2C12AE

Entry point:
68, 62, D7, 66, 52, E8, EA, F7, FD, FF, 0F, 76, 99, 89, C0, A3, 1B, F5, 1C, 96, E5, C3, 59, E9, C6, BA, 64, 40, A3, 78, 64, 22, 7F, 66, 4D, 5E, 6D, C4, 7F, 0C, 70, A4, D5, A6, 6C, 50, B8, CC, D2, 2C, 1F, AB, 26, 9E, 3F, 1C, 07, 87, C5, 88, AC, 81, BA, 45, 51, 72, C8, 3F, D6, A5, 55, 3E, 38, 2E, 0D, AC, 4D, 5A, F7, 3E, 38, D6, AF, F6, A0, BB, 20, C1, C7, 35, 78, CB, 38, 9A, 8D, 19, 47, 71, FC, E5, 1E, A6, C2, A7, A0, FC, 6C, 11, 76, 54, 63, 5F, 19, 43, 88, BE, D1, 88, 38, 81, 0D, 2C, 5F, FF, 9B, A1, 39, E2...
 
[+]

Code size:
2.1 MB (2,151,936 bytes)