iobitdownloader_installmonetizer.exe

Software downloader

The application iobitdownloader_installmonetizer.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from ru.iobit.com.
Publisher:
Software downloader

Product:
Software downloader

Description:
iobitdownloader

Version:
1.0.0.0

MD5:
9b813e4d9599fb082df212ab9322cf60

SHA-1:
f26bfa00f3066e7b2e7ebc61663218c3d85899f7

SHA-256:
829215fd5d81e5c8145c91b42022c46bf13f7745b23435316b697d76ce2dcb73

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 11:13:07 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2356609
354

Agnitum Outpost
Riskware.Agent
7.1.1

avast!
Win32:Malware-gen
2014.9-160215

Baidu Antivirus
PUA.MSIL.IObit
4.0.3.16215

Bitdefender
Trojan.GenericKD.2356609
1.0.20.230

Dr.Web
Program.Unwanted.206
9.0.1.046

Emsisoft Anti-Malware
Trojan.GenericKD.2356609
8.16.02.15.01

ESET NOD32
MSIL/IObit.A potentially unwanted (variant)
10.11595

F-Secure
Trojan.GenericKD.2356609
11.2016-15-02_2

G Data
Trojan.GenericKD.2356609
16.2.25

IKARUS anti.virus
PUA.MSIL.Iobit
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.203.15842

McAfee
Artemis!9B813E4D9599
5600.6488

MicroWorld eScan
Trojan.GenericKD.2356609
17.0.0.138

NANO AntiVirus
Riskware.Win32.Unwanted.drdnlo
0.30.24.1357

nProtect
Trojan.GenericKD.2356609
15.05.08.01

Panda Antivirus
Trj/CI.A
16.02.15.01

Trend Micro House Call
TROJ_GEN.R02KH09E715
7.2.46

VIPRE Antivirus
Trojan.Win32.Generic
40056

File size:
48 KB (49,152 bytes)

Product version:
1.0.0.0

Copyright:
Software downloader © 2014

Trademarks:
Software

Original file name:
iobitdownloader.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\iobitdownloader_installmonetizer.exe

File PE Metadata
Compilation timestamp:
10/9/2014 2:27:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:BWjg1Ht/aZy8drCbsAUbSJUabH+8II2vJHhHlmoEw75mYutowLirMZlypXAiXEan:BWk1N/a/drFbkU0sDlZEw75mYutoWKEq

Entry address:
0xCFBE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 48, 00, 00, 80, 10, 00, 00, 00, 60, 00, 00, 80, 18, 00, 00, 00, 78, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
44 KB (45,056 bytes)

The file iobitdownloader_installmonetizer.exe has been seen being distributed by the following URL.

Remove iobitdownloader_installmonetizer.exe - Powered by Reason Core Security