in.the.name.of.the.king.2.two.worlds.2011.480p.brrip.myegy.com.mr.@hmed.rmvb.exe

Daneil Jemoch

This is a WebPick installer that bundles (with very minimal user consent) a number of adware browser extensions using the JustPlug.it browser framework. The application in.the.name.of.the.king.2.two.worlds.2011.480p.brrip.myegy.com.mr.@hmed.rmvb.exe, “Installer for ItsMyApp” by Daneil Jemoch has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the WebPick InstalleRex (Tarma) installer. The file has been seen being downloaded from livetrafficzipmy.info. While running, it connects to the Internet address r1.stylezip.info on port 80 using the HTTP protocol.
Publisher:
ItsMyApp  (signed by Daneil Jemoch)

Product:
ItsMyApp

Description:
Installer for ItsMyApp

Version:
2014.5.11.1437

MD5:
72aa3125b8ab9f805ada91fb1d6ea41e

SHA-1:
b721b5e00a38bd6f2f0fa7eb0cdbc6e685602b78

SHA-256:
0c0254552a6954d31f7a23ea9c84bd65d0df9fc784ed9f1108fa69d92ec3e76f

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses Web-Pick's 'File Product', an Installer which wraps various products and downloads and installs it silently through the process, hosted on TusFiles.

Analysis date:
4/25/2024 10:56:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware (M)
16.8.4.14

File size:
316.3 KB (323,936 bytes)

Product version:
1.0.0.3

Copyright:
Copyright © 2014 ItsMyApp

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
WebPick InstalleRex (Tarma)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\in.the.name.of.the.king.2.two.worlds.2011.480p.brrip.myegy.com.mr.@hmed.rmvb.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/2/2013 7:00:00 AM

Valid to:
9/3/2014 6:59:59 AM

Subject:
CN=Daneil Jemoch, O=Daneil Jemoch, STREET=Dubenskay 3, L=Kiev, S=Kiev, PostalCode=03056, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
49A39B9858F6FBAB7EFD6CE450878DDB

File PE Metadata
Compilation timestamp:
3/12/2013 3:51:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:FrmbUzkuvcBYC47l2xkihNbvnXz3ma0QKctzwl2hvsbHGJC:FrvkuveY3ibXz3UQKctk2hsbv

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Entropy:
7.9517

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file in.the.name.of.the.king.2.two.worlds.2011.480p.brrip.myegy.com.mr.@hmed.rmvb.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

TCP (HTTP):
Connects to c1.stylezip.info  (54.186.255.26:80)

 
http://c1.stylezip.info/?step_id=1&installer_id=299410126&publisher_id=994&source_id=0&page_id=0&country_code=US&locale=US&browser_id=4&download_id=898230378&external_id=0&session_id=1796460756&hardware_id=2095870882&installer_file_name=in.the.name.of.the.king.2.two.worlds.2011.480p.brrip.myegy.com.mr.@hmed.rmvb