minecraft.exe

AVSoftware EOOD

The software installer uses the StartInstall.com download manager which bundles additional adware offers (toolbars and utilities such as the SafeSearch toolbar) during setup. The application minecraft.exe by AVSoftware EOOD has been detected as adware by 5 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from ttb.popdls.com and multiple other hosts.
Publisher:
AVSoftware EOOD  (signed and verified)

MD5:
efbcdf30daa8c436b0e9362c91a9d9ec

SHA-1:
2107ad621ddfbeacee068f63824db390a9604e5a

SHA-256:
b65689378f3a7d9157bb7a1252f067118fb8c20a3b2f551153d98b42172e3bd4

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
4/27/2024 12:49:08 AM UTC  (today)

Scan engine
Detection
Engine version

herdProtect (fuzzy)
2014.11.10.5

Malwarebytes
PUP.Optional.SoftM8.A
v2014.09.13.07

Qihoo 360 Security
Malware.QVM11.Gen
1.0.0.1015

Reason Heuristics
PUP.AVSoftwareEOOD.J
14.9.13.19

Trend Micro House Call
HV_ZYX_CA082E56.TOMC
7.2.272

File size:
960 KB (983,048 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\minecraft.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/5/2013 12:00:00 AM

Valid to:
6/4/2016 12:59:59 AM

Subject:
CN=AVSoftware EOOD, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AVSoftware EOOD, L=Sofia, S=Sofia, C=BG

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0EB840FECC84AE6DCA7A92109E2314ED

File PE Metadata
Compilation timestamp:
9/8/2014 9:26:33 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:22V9uSWpPUQOiydvby0yzz3k12grzM+lylqqdEyB2uH+6qSegENB:26ufPUQNGqngv2Yqjsp6qSegu

Entry address:
0x3004D0

Entry point:
60, BE, 00, 70, 61, 00, 8D, BE, 00, A0, DE, FF, C7, 87, 18, CA, 26, 00, 07, 10, C2, 4A, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.9210

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
936 KB (958,464 bytes)

The file minecraft.exe has been seen being distributed by the following 2 URLs.

Remove minecraft.exe - Powered by Reason Core Security