mediaget_id4943757ids2s.exe

mediaget-installer Module

Media Get LLC

The application mediaget_id4943757ids2s.exe, “MediaGet installer” by Media Get has been detected as a potentially unwanted program by 12 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from mediaget.com and multiple other hosts.
Publisher:
MediaGet LLC  (signed by Media Get LLC)

Product:
mediaget-installer Module

Description:
MediaGet installer

Version:
1.0

MD5:
7ab7e68653d9a60a048137b1e1205882

SHA-1:
4b4d6794fde1a0cf5a38172edf8b2f537f52dc9e

SHA-256:
bae4e47540d1a0aeb913fc6cb34717ae43dacd4029ce96655d799656a6131ce2

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 12:18:29 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/MediaGet.Gen5
7.11.125.180

AVG
Luhe.MediaGet.B
2014.0.3615

Emsisoft Anti-Malware
Rogue.Win32.GuardSoft
8.13.12.25.10

ESET NOD32
Win32/MediaGet (variant)
7.9307

Fortinet FortiGate
Adware/MediaGet
1/19/2014

G Data
Win32.Adware.MediaGet
13.12.24

Kaspersky
not-a-virus:HEUR:Downloader.Win32.MediaGet
14.0.0.4568

Malwarebytes
PUP.Adware.MediaGet
v2013.12.25.10

McAfee
Artemis!7AB7E68653D9
5600.7271

Reason Heuristics
Optional.MediaGetApp.Installer.MediaGet.X
14.2.20.20

Sophos
MediaGet
4.96

Trend Micro House Call
TROJ_GEN.F47V1223
7.2.359

File size:
845.3 KB (865,568 bytes)

Product version:
1.0

Copyright:
Copyright (c) 2011 MediaGet LLC

Original file name:
mediaget-installer.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\mediaget_id4943757ids2s.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/9/2011 4:00:00 AM

Valid to:
3/9/2014 3:59:59 AM

Subject:
CN=Media Get LLC, O=Media Get LLC, STREET=Sadovaya 53, L=Saint-Petersburg, S=Russia, PostalCode=190344, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
71D26D579AEE6A768F27CF3B6D4E9A91

File PE Metadata
Compilation timestamp:
12/23/2013 9:14:40 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:uhedZZlCfc/xEpL1YwMNsNx8qBz9SYYjqtvN33sUndOCGNSRAM8NCWHuHFYh/9sP:uhePqcJs1Y4VZSYbNN33s1NAINNpcS34

Entry address:
0x1A7AB0

Entry point:
60, BE, 00, A0, 54, 00, 8D, BE, 00, 70, EB, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Code size:
376 KB (385,024 bytes)

The file mediaget_id4943757ids2s.exe has been seen being distributed by the following 34 URLs.

http://mediaget.com/torrent.php?r=indiroyunu.com&fu=http://z.gametop.com/.../City_Racing.exe&f=City-Racing-downloader

http://mediaget.com/download.php?ref_id=yandex&os=windows

http://ld.mediaget.com/index2.php?l=ru&u=http://youtor.org/.../download.php?id=274131&r=youtor.org&f=u041fu043eu043au0430-u0441u0442u0430u043du0438u0446u0430-u0441u043fu0438u0442-u0441u043cu043eu0442u0440u0435u0442u044c-u043eu043du043bu0430u0439u043d-u0441u043au0430u0447u0430u0442u044c-u0442u043eu0440u0440u0435u043du0442-u0441u043au0430u0447u0430u0442u044c-u041fu043eu043au0430-u0441u0442u0430u043du0438u0446u0430-u0441u043fu0438u0442-u0432-u0445u043eu0440u043eu0448u0435u043c-u043au0430u0447u0435u0441u0442u0432u0435-u0432u0441u0435-u0441u0435u0440u0438u0438&s=???? ??????? ???? ???????? ?????? ??????? ???????, ??????? ???? ??????? ???? ? ??????? ???????? ??? ?????&bbls_client_id=18276514&bbl=1

http://sub2.bubblesmedia.ru/go/?link=sKFxDYI/v39eiep6MF6lLTwDv1/e26X1hRKyPadanF5jucv 9/hc668U1G5rNS4pZMecgn7bju 7Ge/o/1/fe1MPhshZA/e1/XCrhTvfbEEbOXDfh 8P git7C/.../A xkubV 3MKTLtf1isPdwTm6A=&param=XBM2U38CBAk=&rid=968&s=? ??????????? ????? ?? ?????????&r=dreamkino.net&f=? ??????????? ????? ?? ?????????&cs=windows-1251&u=

http://mediaget.com/download.php?os=windows

http://sub2.bubblesmedia.ru/go/?link=hRFxS8 Q47bADuO3VRSM yIoe/z3pSJaqyfHhe5Cd5fyzbgrqGEMsjAs5mtB9RwZGFZKSyvVZQtRNRjv8qv3cpBy/qsYBgU7gpWK0S4igTDZo9qUSFAe68OKy0l4 e6ZnyWgFDvXoN4zn2G DhV/.../DzSkwcsuXk6btyoXpLmxqHuyy EQfWL&param=Y 77Fu5vAkY=&rid=1041&s=???????????? ??? 7 ????? ???????? ?????? ?????????. 1 ????? ?? ??????? ????? (S01E07)&r=seria-online.ru&f=???????????? ??? 7 ????? ???????? ?????? ?????????. 1 ????? ?? ??????? ????? (S01E07)&cs=UTF-8&u=

http://sub2.bubblesmedia.ru/go/?link=N9GwENAysVpV5Ano1lkAowctie701EqnQAxJfRN0hRAqpQNo8W yqUM/lYun8 eAszJHQpLAGLoUE4UxoEnR/IL21H4f1EPHsQpGRGe8cdwwhvbcwzM K0livnpUt7uOxdXxJDcqntvTA2IXLvQ9 F4QvCsFRyL4umr mtkyZgA5OgzDmTLLQP4=&param=wyjT42Ju5nc=&rid=418&s=????????? /.../ Genghis Khan (30 ????? ?? 30) (??? ???????) [?????, 2006 ?., ???????????? ??????, 6xDVD9]&cs=windows-1251&u=

Latest 30 of 34 download URLs

Remove mediaget_id4943757ids2s.exe - Powered by Reason Core Security