gwiezdne wojny przebudze_10924_i129867498_il345.exe

Pixillion

AITI Strim CONSULTING, TOV

The application gwiezdne wojny przebudze_10924_i129867498_il345.exe, “Pixillion Image Converter” by AITI Strim CONSULTING, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
NCH Software  (signed by AITI Strim CONSULTING, TOV)

Product:
Pixillion

Description:
Pixillion Image Converter

Version:
2.96+

MD5:
a521698e51daf07696756fe3199d77ce

SHA-1:
9ba5abec0ac4c4cadab41643470c7a0641db05cc

SHA-256:
eed562aa7260c2a88b21f07f77abc2f3d6b02be88a6756b1629fb9fc7f900c75

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 3:57:49 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize.AITIStri (M)
16.4.16.8

File size:
2.1 MB (2,239,440 bytes)

Product version:
2.96+

Copyright:
NCH Software

Original file name:
Pixillion.exe

File type:
Executable application (Win32 EXE)

Language:
English (Australia)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\gwiezdne wojny przebudze_10924_i129867498_il345.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/11/2016 1:00:00 AM

Valid to:
1/11/2017 12:59:59 AM

Subject:
CN="AITI Strim CONSULTING, TOV", OU=IT, O="AITI Strim CONSULTING, TOV", STREET="Bud. 53-55, vul.Pochainynska", L=Kyyiv, S=Kyyiv, PostalCode=04080, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5A7A1CB365BD8EA3567456D3B8166630

File PE Metadata
Compilation timestamp:
1/26/2016 5:52:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:z3YvOj/egr7QXw1DfbbS93wmPX9HN+bIF7lg:z3Y2egr7ow1D4tEUF7lg

Entry address:
0x4AABBE

Entry point:
68, 9C, 4E, D2, C8, E8, 1B, AF, E0, FF, 39, 98, 8F, B9, AF, 9F, E3, 6C, 72, 31, 8D, 9E, 98, B9, 91, ED, 5D, 1C, BF, D2, 04, CA, 32, BF, 5C, 60, EC, BA, 64, 4E, BF, 1F, 22, 21, C0, 92, E3, DA, 98, 2B, CE, ED, BD, 36, DC, 7C, EC, BC, 31, 6F, 22, 1C, 20, BA, 6F, 5D, 4E, 29, 15, 88, D9, 5D, 9F, 60, 74, 25, 48, 05, 79, 40, 35, 0B, 34, 88, DF, 20, 83, 86, C0, EA, 95, BA, 87, C0, 31, 87, E5, 74, 23, 5D, E4, 4A, 79, 44, 26, BA, 6E, 79, 40, DF, F2, BC, 78, 45, E6, CE, D5, 8B, DD, 89, 0A, 31, 74, 25, 1C, 0B, 7C, 74...
 
[+]

Code size:
2.1 MB (2,222,592 bytes)