operation+research+by+kan_10924_i67174059_il345.exe

StringEncrypt

A4 TOV

The application operation+research+by+kan_10924_i67174059_il345.exe by A4 TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
PELock Software  (signed by A4 TOV)

Product:
StringEncrypt

Version:
1.0.0.0

MD5:
2992d69a7fb40bb6e0ad623f389cb3dc

SHA-1:
4c855860786defb123b6f6959b0ecb5e5f60de92

SHA-256:
861571159715261122077a01a04467558b8775430e8106eb392e977c63a21ad0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/13/2024 3:54:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize (M)
17.3.3.3

File size:
1.5 MB (1,590,752 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Bartosz Wójcik 2013

Original file name:
StringEncrypt.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\operation+research+by+kan_10924_i67174059_il345.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/17/2015 5:30:00 AM

Valid to:
9/17/2016 5:29:59 AM

Subject:
CN=A4 TOV, O=A4 TOV, STREET=Bud. 29 vul.Shchorsa, L=Kiev, S=Kiev, PostalCode=01010, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
27FB5DEC4CCFD4F3CF69A6B639C6AD4B

File PE Metadata
Compilation timestamp:
10/4/2015 3:12:43 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x35395A

Entry point:
68, 52, 31, 24, CF, E8, F9, 11, EA, FF, 32, AE, B9, C8, 55, FB, 42, AC, 49, 3A, 95, 96, 21, 16, EE, 59, 5D, AF, 7A, 58, FE, 7B, F9, C2, D8, 76, 16, 0F, 61, 3C, 6B, 59, 71, 5D, DA, 6C, 97, EF, C3, 43, E4, 72, 6F, EC, A5, 0A, BD, 1B, A7, 9C, 32, 3C, C8, 4A, FB, 5C, 3E, 2D, 03, 4B, FD, 60, FB, BF, 36, 0E, E2, EF, BC, 2A, AD, 5C, AA, 34, 2A, 13, C9, 2B, E3, CF, 5B, 8E, 16, 01, 60, CE, 06, C8, AF, F9, AF, 76, 86, 4F, 9B, CD, 9D, F4, B2, A1, A2, 05, 55, 5B, CC, 9B, C9, 5D, 82, D4, 30, 92, B4, F4, A3, 66, 72, E9...
 
[+]

Entropy:
7.9756  (probably packed)

Code size:
1.5 MB (1,568,768 bytes)