mediaplayer__9251_i1073063340_il240.exe

KOMPANIYA КRЕАТА LLC

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application mediaplayer__9251_i1073063340_il240.exe by KOMPANIYA КRЕАТА has been detected as adware by 18 anti-malware scanners. The program is a setup application that uses the Amonetize Downloader installer. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
KOMPANIYA КRЕАТА LLC  (signed and verified)

Version:
1.1.5.89

MD5:
b527e684059636a7cb80e54af87dc6af

SHA-1:
d50ce3884ecc53cb62f763dec4aa0603d257e7a8

SHA-256:
0ab9e145db3abcdb0903d98af3dc6536b8d72142235e2291ffa8d6db6becf290

Scanner detections:
18 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 5:38:31 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Amonetize.N
926

AhnLab V3 Security
PUP/Win32.Amonetiz
2014.07.22

avast!
Win32:Amonetize-CL [PUP]
2014.9-140723

AVG
Generic
2015.0.3404

Baidu Antivirus
Adware.Win32.Amonetize
4.0.3.14723

Bitdefender
Application.Bundler.Amonetize.N
1.0.20.1020

Dr.Web
Adware.Downware.5913
9.0.1.0204

ESET NOD32
Win32/Amonetize.BI (variant)
8.10132

F-Secure
Application.Bundler.Amonetize
11.2014-23-07_4

G Data
Application.Bundler.Amonetize
14.7.24

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
14.0.0.3516

Malwarebytes
PUP.Optional.Downloader
v2014.07.23.07

MicroWorld eScan
Application.Bundler.Amonetize.N
15.0.0.612

NANO AntiVirus
Riskware.Win32.Amonetize.dchxoa
0.28.2.60990

Panda Antivirus
Trj/CI.A
14.07.23.07

Qihoo 360 Security
Win32/Application.bcb
1.0.0.1015

Reason Heuristics
PUP.Installer.KOMPANIYAR.d
14.7.23.19

VIPRE Antivirus
Amonetize
31478

File size:
342.2 KB (350,432 bytes)

Product version:
1.1.5.89

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Amonetize Downloader

Language:
English (United States)

Common path:
C:\users\{user}\downloads\mediaplayer__9251_i1073063340_il240.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/15/2014 6:00:00 PM

Valid to:
6/16/2015 5:59:59 PM

Subject:
CN=KOMPANIYA КRЕАТА LLC, O=KOMPANIYA КRЕАТА LLC, L=Kharkiv, S=Kharkiv, C=UA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
04CA5D77531C0E61E4DE2CB0E6E4B5B2

File PE Metadata
Compilation timestamp:
7/21/2014 3:04:12 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:KBieRGukt2xUBTBI/R9VqRuLxDD+yR4Rlu3XrNkJyWa5Jp:EvsN2xUBTO/q+xH+lu3XreFa5Jp

Entry address:
0x14C32

Entry point:
E8, E8, 5F, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 3C, 8E, 3F, 00, 00, 75, 18, E8, C8, 59, 00, 00, 6A, 1E, E8, 12, 58, 00, 00, 68, FF, 00, 00, 00, E8, 10, F6, FF, FF, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, 3C, 8E, 3F, 00, FF, 15...
 
[+]

Entropy:
7.4370

Code size:
116.5 KB (119,296 bytes)

The file mediaplayer__9251_i1073063340_il240.exe has been seen being distributed by the following 4 URLs.

http://www.new-hdplugin.com/direct-download.html?version=1.1.5.89&iaff1=9982&ci=4651&capp=FlashPlayer&ti1=ZldXVpZD1lZmExZGU5MS02ZGM0LTQ2MTAtOGMwNy0xNGU4YzgxMWZlNTU

http://www.more-files.com/allddT.html?myref=www.livesoccer2014.com&version=1.1.5.89&prefix=TVapp&campid=8821&capp=TvAppMondial&ti1=18395808411405983346&AMt=1405983364577&AMh=7fn2b4gxIWmb09igS84d2Ie2zMXUjQgM3KAUfCzDKPbVydo5QZMSwcespsmVBC1AtdCH3iBb48loOaw3

Remove mediaplayer__9251_i1073063340_il240.exe - Powered by Reason Core Security