Mac OS X 10.8 Mountain Lion ISO Untouched.exe

Appit

Roman Malinenko

This program bundles adware during the download and install process using the InstaleRex pay-per-install app monetizer. The application Mac OS X 10.8 Mountain Lion ISO Untouched.exe, “Installer for Appit” by Roman Malinenko has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Tarma (InstalleRex) standalone installer. The file has been seen being downloaded from lp.ezdownloadpro.info. While running, it connects to the Internet address r1.stylezip.info on port 80 using the HTTP protocol.
Publisher:
GreatSoft  (signed by Roman Malinenko)

Product:
Appit

Description:
Installer for Appit

Version:
2014.2.13.1623

MD5:
6efb001fc37cb0ab977d2d357fcb2867

SHA-1:
be29516305c0aaf9be79ab1994f0e4b80e15dd6e

SHA-256:
537228d253244efc2d7c82e012a35c83c53f0dbcee3693c5c2feba485f673a9e

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses Web-Pick's 'File Product', an Installer which wraps various products and downloads and installs it silently through the process, hosted on TusFiles.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
8/8/2014 4:04:52 AM UTC  (19 days ago)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.WebPick.Installer.i
14.8.8.0

File size:
313.7 KB (321,224 bytes)

Product version:
1.0.0.2

Copyright:
Copyright © 2014 GreatSoft

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
Tarma (InstalleRex) standalone

Language:
Language Neutral

Common path:
C:\users\user\downloads\mac os x 10.8 mountain lion iso untouched.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/19/2013 3:00:00 AM

Valid to:
8/20/2014 2:59:59 AM

Subject:
CN=Roman Malinenko, O=Roman Malinenko, STREET=Esplanadna 17, L=Kyev, S=Kyev, PostalCode=01001, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
47E3645CFB0C3CB8130567C3E5223C1D

File PE Metadata
Compilation timestamp:
3/12/2013 10:51:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:+rY9uEo2S1YnQmCX492DkwNP3qpYFG+NFJCWE0ALKkizq+o8Ixc+pwymEVwk9pYp:+rwu6/eIo4KfJs0ALK5q+GxcXBER9p4

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Code size:
7.5 KB (7,680 bytes)

The file Mac OS X 10.8 Mountain Lion ISO Untouched.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

TCP (HTTP):
Connects to c1.stylezip.info  (54.186.255.26:80)

 
http://c1.stylezip.info/?step_id=1&installer_id=2345556&publisher_id=345&source_id=0&page_id=0&country_code=US&locale=US&browser_id=4&download_id=7036668&external_id=0&session_id=14073336&hardware_id=16418892&installer_file_name=Mac+OS+X+10.8+Mountain+Lion+ISO+Untouched

1 / 68      (Adware)
navman_f20_-_europa_iso.rar.000.exe  (f7d4bc8e0b33ff9d63412d879d72e362ec08021f)

1 / 68      (Adware)
removewat 2.2.7 windows 7 activation working.exe  (b846573eb814227b66c6fd2eb90d00e5cea64604)

1 / 68      (Adware)
languard 2014 keygen.exe  (8c514b5ce28a33a3a86908774721395627b535f3)

24 / 68    (Adware)
_-_en-us by 4youtech.com.rar.exe  (703934dd48fe82d6a1c7ce4d928dc5aacf2edbf8)

1 / 68      (Adware)
filemaker pro 13 advanced.rar.exe  (231a3ee7b8ba42171bdd494140bd2c7572ae7285)

1 / 68      (Adware)
winsetupfromusb 0-2-2.exe.exe  (b003d90cf7499fbf3affa46ee052bed0ee5b5120)

1 / 68      (Adware)

1 / 68      (Adware)
bein news_by_hichrawi-streaming.all.rar.exe  (16373014d7333eeab52792f76d8098666545197c)

33 / 68    (Adware)
streamtn.v1.05.rar.exe  (abc46237d02e416ab6095ed976f7a2be880dc2dc)

33 / 68    (Adware)
vogel quantitative inorganic.exe  (b1443e193f24906804cb73cc0afd8a24502dfc8d)

30 / 68    (Adware)
idm.6055.silent.install.exe.exe  (33494043bb5bee8e4e02dbf7368c974a7840133f)

31 / 68    (Adware)
cisco packet tracer 6.0.1 for windows (with tutorials).exe.exe  (088a2e7243e4a1123ad9fac064fa9b917316e2cd)

31 / 68    (Adware)
isobuster pro 3.3 build 3.3.0.0 final+key.exe  (e1d55f7f9eb534247ddfa0a962be6abacbb98da8)

30 / 68    (Adware)

30 / 68    (Adware)
itdunyablog - a large platform of apps n games..exe  (9b51faa333d87df766a53f9f90359fa0b7581709)

32 / 68    (Adware)
atomix virtual dj pro 7.4 full version free download with crack.exe  (5f5b8b971bd2641c4cf8b8ebfc125268925015b7)

Detection Incidence by Country