idm active by m0shaks.exe

Maxiget Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application idm active by m0shaks.exe by Maxiget Limited has been detected as adware by 23 anti-malware scanners. It is also typically executed from the user's temporary directory.
Publisher:
Maxiget Limited  (signed and verified)

Version:
3, 3, 55, 0

MD5:
cd1a4120d754b18e3afc00aa38210d4f

SHA-1:
e0eb439f7cd6e432a0f90f19de78a918a055ca69

SHA-256:
338df61279cad476309374d4bda5ab65bd3f9ed6c10ae5649742a74bbed14b62

Scanner detections:
23 / 68

Status:
Adware

Explanation:
This is a modified installer version of the software and bundles additional offers including adware.

Analysis date:
4/26/2024 2:11:11 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.151954
890

Agnitum Outpost
PUA.4Shared
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.169.216

AVG
Generic
2015.0.3368

Bitdefender
Gen:Variant.Graftor.151954
1.0.20.1205

Comodo Security
Application.Win32.4Shared.K
19348

Dr.Web
Adware.Downware.1751
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Graftor.151954
9.0.0.4324

ESET NOD32
Win32/4Shared.U potentially unwanted application
7.0.302.0

F-Prot
W32/A-22cc26dc
v6.4.7.1.166

F-Secure
Gen:Variant.Graftor.151954
11.2014-29-08_6

G Data
Gen:Variant.Graftor.151954
14.8.24

IKARUS anti.virus
PUA.4Shared
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.183.13198

Malwarebytes
PUP.Optional.4Shared
v2014.08.29.12

McAfee
PUP-FNX
5600.7024

MicroWorld eScan
Gen:Variant.Graftor.151954
15.0.0.723

NANO AntiVirus
Riskware.Win32.Downware.ddwtfv
0.28.2.61861

Panda Antivirus
Trj/Genetic.gen
14.08.29.12

Reason Heuristics
PUP.MaxigetLimited.V
14.8.28.22

Sophos
4Share Downloader
4.98

VIPRE Antivirus
Threat.4150696
32210

Zillya! Antivirus
Backdoor.PePatch.Win32.39775
2.0.0.1905

File size:
438 KB (448,552 bytes)

Product version:
3, 3, 55, 0

Copyright:
2014

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\idm active by m0shaks.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
6/3/2014 11:41:06 AM

Valid to:
8/15/2016 9:41:32 AM

Subject:
CN=Maxiget Limited, O=Maxiget Limited, L=Limassol, S=Cyprus, C=CY

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
043F9C868704FA

File PE Metadata
Compilation timestamp:
8/8/2014 6:06:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:AsV3WLR3WHchisdVDoqbjqY7D1EbUGJBJFEc29xc5Vz2KEbIX:/ZWdAkDvDoKeY7D1bG/zB2ELz2KFX

Entry address:
0x2C16B

Entry point:
E8, F6, A3, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 14, A1, B8, FD, 44, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 57, 8B, F1, 39, 1D, 04, 16, 45, 00, 75, 38, 53, 53, 33, FF, 47, 57, 68, 94, 4F, 44, 00, 68, 00, 01, 00, 00, 53, FF, 15, 60, 21, 44, 00, 85, C0, 74, 08, 89, 3D, 04, 16, 45, 00, EB, 15, FF, 15, E4, 20, 44, 00, 83, F8, 78, 75, 0A, C7, 05, 04, 16, 45, 00, 02, 00, 00, 00, 39, 5D, 14, 7E, 22, 8B, 4D, 14, 8B, 45, 10, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, 45, 14, 2B, C1...
 
[+]

Entropy:
6.8733

Code size:
256.5 KB (262,656 bytes)

Remove idm active by m0shaks.exe - Powered by Reason Core Security