links_protegidos_(mega)_downloader-n1za7zr2f.exe.zip
The file links_protegidos_(mega)_downloader-n1za7zr2f.exe.zip has been detected as a potentially unwanted program by 20 anti-malware scanners. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from sub.yorkshatb.com.
File name:
links_protegidos_(mega)_downloader-n1za7zr2f.exe.zip
MD5:
c56ca9c8a6219b76cb2a6cc17b4d87e8
SHA-1:
11f3289662a01d0ebfa1c2b56ed55651b56c01af
SHA-256:
a79932ee4cfce10fc77f375ecea1d9c6836c07c2155c557cc366e02cf174e73c
Scanner detections:
20 / 68
Status:
Potentially unwanted
Explanation:
Uses the Somoto 'BetterInstaller' to bundle additional (unwanted) software during install without adequate consent.
Analysis date:
4/25/2024 11:26:00 PM UTC (a few moments ago)
Scan engine
Detection
Engine version
Lavasoft Ad-Aware
Application.Bundler.Somoto.AH
5874736
Avira AntiVirus
PUA/Somoto.Gen2
8.3.1.6
Arcabit
Application.Bundler.Somoto.AH
1.0.0.425
avast!
NSIS:Adware-ZI [PUP]
2014.9-150820
Bitdefender
Application.Bundler.Somoto.AH
1.0.20.1160
Clam AntiVirus
Win.Adware.Somoto
0.98/20809
Dr.Web
Threat.Undefined
9.0.1.05190
Emsisoft Anti-Malware
Application.Bundler.Somoto.AH
10.0.0.5366
ESET NOD32
Win32/Somoto.G potentially unwanted application
7.0.302.0
F-Prot
W32/SomotoBetterInstaller.F.
v6.4.7.1.166
F-Secure
Application.Bundler.Somoto
11.2015-20-08_5
K7 AntiVirus
Trojan
13.2016943
Kaspersky
not-a-virus:HEUR:Downloader.NSIS.Somoto
14.0.0.1554
MicroWorld eScan
Application.Bundler.Somoto.AH
16.0.0.696
NANO AntiVirus
Trojan.Win32.Agent.dtledk
0.30.24.3079
Panda Antivirus
PUP/Somoto
15.08.20.05
Trend Micro House Call
ADW_TOMOS.SMN
7.2.232
Trend Micro
ADW_TOMOS.SMN
10.465.20
VIPRE Antivirus
Trojan.Win32.Generic
43044
File size:
379.5 KB (388,576 bytes)
Common path:
C:\users\{user}\downloads\links_protegidos_(mega)_downloader-n1za7zr2f.exe.zip
The file links_protegidos_(mega)_downloader-n1za7zr2f.exe.zip has been seen being distributed by the following URL.