jsillf.exe

Get your downloads

Maxiget Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application jsillf.exe by Maxiget Limited has been detected as adware by 14 anti-malware scanners. The file has been seen being downloaded from ds123.maxiget.com.
Publisher:
Company #1  (signed by Maxiget Limited)

Product:
Get your downloads

Version:
3, 1, 28, 0

MD5:
685cf045dfceb5792047b1307cd5e2b4

SHA-1:
abac3791059b4dc82b4a5e02f246f2f34f159a91

SHA-256:
439a756449e7c2f7b4c9ce32eae02b17fa7027357aec53ebb4f75ecbfd828cdc

Scanner detections:
14 / 68

Status:
Adware

Explanation:
This is a modified installer version of the software and bundles additional offers including adware.

Analysis date:
4/25/2024 4:39:58 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.4Shared
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.155.180

AVG
Trojan horse Dropper.Agent.BIQP
2014.0.3972

Comodo Security
Application.Win32.Graftor.KLK
18598

ESET NOD32
Win32/4Shared.P potentially unwanted application
7.0.302.0

G Data
Win32.Trojan.TorrentNZ
14.6.24

IKARUS anti.virus
not-a-virus:Downloader.Win32.GetFaster
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.4Shared.A
v2014.06.19.08

McAfee
PUP-FIW
5600.7095

NANO AntiVirus
Trojan.Win32.Agent.ctkcbd
0.28.0.60253

Reason Heuristics
PUP.MaxigetLimited.G
14.8.7.21

Sophos
4Share Downloader
4.98

Vba32 AntiVirus
TrojanDropper.Agent
3.12.26.3

VIPRE Antivirus
Threat.4838292
29708

File size:
374.2 KB (383,200 bytes)

Product version:
3, 1, 28, 0

Copyright:
Copyright (C) 2013

Trademarks:
TM(c)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
8/15/2013 3:41:32 PM

Valid to:
8/15/2016 3:41:32 PM

Subject:
CN=Maxiget Limited, O=Maxiget Limited, L=Limassol, S=Cyprus, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
045BA815265145

File PE Metadata
Compilation timestamp:
1/18/2014 12:48:10 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:l39pEoamDLQk1gn+FADNHxxFm9yIrKW8ttV5wl4:lnEVSLCiAFxxFm9yIrKWwtU4

Entry address:
0x25834

Entry point:
E8, 23, 92, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 14, A1, A0, 3A, 44, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 57, 8B, F1, 39, 1D, CC, 50, 44, 00, 75, 38, 53, 53, 33, FF, 47, 57, 68, 90, B0, 43, 00, 68, 00, 01, 00, 00, 53, FF, 15, 7C, 91, 43, 00, 85, C0, 74, 08, 89, 3D, CC, 50, 44, 00, EB, 15, FF, 15, 70, 90, 43, 00, 83, F8, 78, 75, 0A, C7, 05, CC, 50, 44, 00, 02, 00, 00, 00, 39, 5D, 14, 7E, 22, 8B, 4D, 14, 8B, 45, 10, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, 45, 14, 2B, C1...
 
[+]

Entropy:
6.8205

Code size:
223 KB (228,352 bytes)

The file jsillf.exe has been seen being distributed by the following URL.

Remove jsillf.exe - Powered by Reason Core Security