iljagortchateaufatalenlebookdmt__15022_i1613129039_il3664210.exe.rar

The file iljagortchateaufatalenlebookdmt__15022_i1613129039_il3664210.exe.rar has been detected as a potentially unwanted program by 7 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from www.nice-cat.xyz.
MD5:
7cf5548d691d3cbaa502cb2380c98374

SHA-1:
af2779e26d82488c9a98cf0c2a9fd794deb3b894

SHA-256:
5c346c03724bc2499e6e57b150975af7973b40cc971dab3f1b4ed696ac778375

Scanner detections:
7 / 68

Status:
Potentially unwanted

Analysis date:
5/18/2024 11:16:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Amonetize.BG
5819428

Dr.Web
infected with Trojan.Amonetize.6636
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.Amonetize.BG
10.0.0.5366

ESET NOD32
Win32/Amonetize.HO potentially unwanted application
7.0.302.0

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize
15.0.0.562

McAfee
Program.Artemis!83C5EFFE4BE7
18.0.204.0

Reason Heuristics
PUP.Amonetize (M)
16.1.11.17

File size:
678.7 KB (694,972 bytes)

Common path:
C:\users\{user}\downloads\iljagortchateaufatalenlebookdmt__15022_i1613129039_il3664210.exe.rar

The file iljagortchateaufatalenlebookdmt__15022_i1613129039_il3664210.exe.rar has been seen being distributed by the following URL.