installer47__7934_il20618.exe

The application installer47__7934_il20618.exe has been detected as a potentially unwanted program by 27 anti-malware scanners. This is a setup program which is used to install the application. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from vfastdownload.com.
Version:
1.1.5.90

MD5:
e36268bd4e96da41853778c6d28a42a9

SHA-1:
156df71c6630bc4bd2b59f3e1689ccb1c0043fd6

SHA-256:
c322186c8544e72b14300db88c5e5a78fc4fe307601eb07100b28fb2ab151369

Scanner detections:
27 / 68

Status:
Potentially unwanted

Analysis date:
5/12/2024 10:42:51 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.568839
538

Agnitum Outpost
PUA.Amonetize
7.1.1

AhnLab V3 Security
PUP/Win32.Amonetiz
2015.04.04

Baidu Antivirus
PUA.Win32.Amonetize
4.0.3.15815

Bitdefender
Gen:Variant.Kazy.568839
1.0.20.1135

Bkav FE
HW32.Packed
1.3.0.6379

Comodo Security
Virus.Win32.Virut.CE
21637

Dr.Web
Trojan.DownLoader12.46038
9.0.1.0227

Emsisoft Anti-Malware
Gen:Variant.Kazy.568839
8.15.08.15.06

ESET NOD32
Win32/Amonetize.EA potentially unwanted (variant)
9.11422

Fortinet FortiGate
Riskware/Amonetize
8/15/2015

F-Secure
Gen:Variant.Kazy.568839
11.2015-15-08_7

G Data
Gen:Variant.Kazy.568839
15.8.25

K7 AntiVirus
Trojan
13.202.15480

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
14.0.0.1576

Malwarebytes
PUP.Optional.Amonetize
v2015.08.15.06

McAfee
RDN/Generic PUP.z!ff
5600.6672

MicroWorld eScan
Gen:Variant.Kazy.568839
16.0.0.681

NANO AntiVirus
Riskware.Win32.Amonetize.dowwri
0.30.8.659

Panda Antivirus
Generic Suspicious
15.08.15.06

Qihoo 360 Security
HEUR/QVM16.0.Malware.Gen
1.0.0.1015

Quick Heal
(Suspicious) - DNAScan
8.15.14.00

Sophos
Generic PUA BF
4.98

Trend Micro House Call
TROJ_GEN.R021C0EC615
7.2.227

Trend Micro
TROJ_GEN.R021C0EC615
10.465.15

Vba32 AntiVirus
AdWare.Amonetize
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
39028

File size:
704.5 KB (721,408 bytes)

Product version:
1.1.5.90

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\installer47__7934_il20618.exe

File PE Metadata
Compilation timestamp:
2/25/2015 5:01:10 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:N/Q8Ai26ieM+7Gb6pOCe+28inVoSeqqOyJtrf1C7V7+m8CvKp:y8Axvb6pOO2gqqOqtrNaIpsK

Entry address:
0x133FB2

Entry point:
E8, F6, 48, F9, FF, 45, 8D, 6C, CD, FC, 7A, 28, 6A, F6, 2A, 9E, 3A, 3C, 88, D0, 40, A8, 78, 70, D0, 00, C0, CA, 42, B2, 6E, 5E, 82, FE, FA, 9D, 35, 71, 81, 8C, E2, 11, D1, 52, 63, 9B, FA, BA, BD, 55, BD, 59, B1, 49, 78, C2, 12, 6D, 08, A0, E4, 4C, D6, D3, 28, 17, 2B, 15, 28, 11, 4E, C0, BC, AA, 89, 13, BB, 4E, 49, E4, 51, 02, AE, 1A, 57, EA, 7A, C6, 13, 1D, 1A, 57, 96, 51, D4, 11, ED, 0C, 43, 8E, 19, B4, 14, 56, 1E, F2, 9C, 68, 36, F2, A7, 99, 0A, F3, AF, 4B, C6, 07, D4, F4, 81, 18, B4, F8, 93, 94, 67, F7...
 
[+]

Entropy:
7.8643  (probably packed)

Code size:
353 KB (361,472 bytes)

The file installer47__7934_il20618.exe has been seen being distributed by the following URL.

Remove installer47__7934_il20618.exe - Powered by Reason Core Security