m2d.25g.by.zezoabed-eslam_10924_i129837637_il345.exe

PDF Decrypter Pro

AITI Strim CONSULTING, TOV

The application m2d.25g.by.zezoabed-eslam_10924_i129837637_il345.exe, “PDF Decrypter Pro 3.60 ” by AITI Strim CONSULTING, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
pdfdecrypter.com   (signed by AITI Strim CONSULTING, TOV)

Product:
PDF Decrypter Pro

Description:
PDF Decrypter Pro 3.60

MD5:
8734fdd15a83be4def4fb23110688901

SHA-1:
ad5c84e1533237b89aa7d099f9da916e7cab0997

SHA-256:
f42655e9d832cab7ae4f12faecc808e038c6cd55efb5cbd26deca5280fa6f135

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 3:58:18 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize.AITIStri (M)
16.5.6.9

File size:
2.1 MB (2,222,936 bytes)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\m2d.25g.by.zezoabed-eslam_10924_i129837637_il345.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/10/2016 4:00:00 PM

Valid to:
1/10/2017 3:59:59 PM

Subject:
CN="AITI Strim CONSULTING, TOV", OU=IT, O="AITI Strim CONSULTING, TOV", STREET="Bud. 53-55, vul.Pochainynska", L=Kyyiv, S=Kyyiv, PostalCode=04080, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5A7A1CB365BD8EA3567456D3B8166630

File PE Metadata
Compilation timestamp:
1/26/2016 4:02:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:m8uqNhaNe6uZ1XzipGaqkedu19IocKcwhsztPokasKJHf+Qf:vjOcb3epZLe019bcfnztVasKJ/rf

Entry address:
0x2B8770

Entry point:
68, 82, F5, 6A, 73, E8, F3, 67, FF, FF, 3B, E0, C1, EF, 05, F5, E9, 2D, A6, 09, 00, BD, 30, 53, 2B, 6D, 21, C5, AC, D4, BC, C4, C4, AC, D4, C5, AD, F6, AC, D4, 3C, 50, CF, AC, D4, 38, 78, B3, 53, 2B, 33, 6B, 7E, AC, D4, EA, BE, 71, AC, D4, AD, 09, 16, AC, D4, 09, 69, 97, 53, 2B, 84, CC, 1F, 53, 2B, B9, DD, 13, 53, 2B, 45, 11, A9, AC, D4, B9, F5, E2, AC, D4, 4A, 26, E9, AC, D4, 1C, 39, 53, 2B, 78, 00, E3, AC, D4, AF, 0A, C5, 18, 12, 08, 26, D4, 3A, 52, 1A, 26, D4, 02, 4E, EA, D9, 2B, 7C, 24, 7C, 26, D4, ED...
 
[+]

Entropy:
7.9721  (probably packed)

Code size:
2.1 MB (2,207,232 bytes)