hide my ip 5.3 patch serial(full).exe

CHummer

New IT Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application hide my ip 5.3 patch serial(full).exe, “Description is empty” by New IT Limited has been detected as adware by 6 anti-malware scanners. The file has been seen being downloaded from 4sx.getafilefast.net.
Publisher:
Elit -e - Company  (signed by New IT Limited)

Product:
CHummer

Description:
Description is empty

Version:
3, 5, 13, 0

MD5:
8d7612e2a9325e85c25ffcb2bc2d19c1

SHA-1:
d3105339c7781817d6d2c38c402c3a70e64f36e2

SHA-256:
ad9235b8355f4280bebad6428a0d1f7b570a77465bb9ed8e7c94b837a16c437f

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
5/24/2024 7:54:18 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downloader.Gen8
7.11.171.22

AVG
Generic
2015.0.3360

Dr.Web
Adware.Downware.2538
9.0.1.05190

ESET NOD32
probably Win32/4Shared.X potentially unwanted application
7.0.302.0

Reason Heuristics
PUP.NewITLimited.a
14.10.1.11

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

File size:
42 KB (42,984 bytes)

Product version:
3, 5, 13, 0

Copyright:
2014

Trademarks:
No

Original file name:
DHelper

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\hide my ip 5.3 patch serial(full).exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
5/14/2014 1:00:04 PM

Valid to:
12/30/2016 7:33:53 AM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
049768F7F19C91

File PE Metadata
Compilation timestamp:
9/5/2014 4:53:24 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:UOwfivq/RsoZNUYbmSChHUborYp9vZ12CTCH9t0InRj:u3mhhfYp9x12CTCdt0IF

Entry address:
0x3210

Entry point:
55, 8B, EC, 83, E4, F8, 83, EC, 0C, 53, 56, 57, 8D, 44, 24, 10, 50, C7, 44, 24, 14, 08, 00, 00, 00, C7, 44, 24, 18, 20, 00, 00, 00, FF, 15, 00, 40, 40, 00, 68, 28, 0A, 00, 00, 68, A0, 1F, B9, 00, 6A, 00, FF, 15, 94, 40, 40, 00, 6A, 00, 68, 80, 00, 00, 00, 6A, 03, 6A, 00, 6A, 01, 68, 00, 00, 00, 80, 68, A0, 1F, B9, 00, FF, 15, 8C, 40, 40, 00, 8B, F8, 83, FF, FF, 0F, 84, 30, 01, 00, 00, E8, BA, E3, FF, FF, 57, 8B, 3D, 90, 40, 40, 00, 8A, D8, FF, D7, 84, DB, 0F, 84, 18, 01, 00, 00, 66, 83, 3D, C8, A0, 40, 00...
 
[+]

Entropy:
5.6981

Developed / compiled with:
Microsoft Visual C++

Code size:
9 KB (9,216 bytes)

The file hide my ip 5.3 patch serial(full).exe has been seen being distributed by the following URL.

Remove hide my ip 5.3 patch serial(full).exe - Powered by Reason Core Security