inazuma eleven go strike...phin all unlocked.7z.exe

SuperCharging

New IT Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application inazuma eleven go strike...phin all unlocked.7z.exe by New IT Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from ds312.maxiget.com.
Publisher:
SPC LLC  (signed by New IT Limited)

Product:
SuperCharging

Description:
DWD

Version:
3, 3, 17, 0

MD5:
964d13f6b90ab01debb208f4a06884d5

SHA-1:
43100f593a6af0c82aff27162ef016682f06472e

SHA-256:
a4f3428b7234a300b1173efc40e2538d303b83788c3949d0e379b7146b0893f8

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 10:03:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.New IT Limited.NewIT (M)
16.2.12.20

File size:
459 KB (470,048 bytes)

Product version:
3, 3, 17, 0

Copyright:
2013

Trademarks:
-

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\inazuma eleven go strike...phin all unlocked.7z.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
4/10/2014 9:50:45 PM

Valid to:
12/30/2016 2:33:53 PM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B90BA60B54B37

File PE Metadata
Compilation timestamp:
4/17/2014 11:26:16 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:LneADuJuYPG6g3uFLnd2wSFfJUQwhinV26tKkJZXlBu3iOq:LndDahG6g3I2wWfqrhiV2+LVBuyp

Entry address:
0x29944

Entry point:
E8, 54, 98, 00, 00, E9, 78, FE, FF, FF, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D, 41, FE, 8B, 4C, 24, 04...
 
[+]

Entropy:
6.4737

Code size:
316 KB (323,584 bytes)

The file inazuma eleven go strike...phin all unlocked.7z.exe has been seen being distributed by the following URL.