overlord+vostfr_10924_i64984711_il345.exe

StringEncrypt

A4 TOV

The application overlord+vostfr_10924_i64984711_il345.exe by A4 TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
PELock Software  (signed by A4 TOV)

Product:
StringEncrypt

Version:
1.0.0.0

MD5:
b4a4906a0c24893ab6f963bbfb1d8f61

SHA-1:
99f7cda6c246194325f554a0922f4f5de1302e52

SHA-256:
0a3b060b8077771383f77faea805e2dadf707b016c891be63261af5ff3ca8274

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/12/2024 9:59:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize (M)
17.3.3.2

File size:
1.5 MB (1,570,272 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Bartosz Wójcik 2013

Original file name:
StringEncrypt.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\overlord+vostfr_10924_i64984711_il345.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/17/2015 2:00:00 AM

Valid to:
9/17/2016 1:59:59 AM

Subject:
CN=A4 TOV, O=A4 TOV, STREET=Bud. 29 vul.Shchorsa, L=Kiev, S=Kiev, PostalCode=01010, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
27FB5DEC4CCFD4F3CF69A6B639C6AD4B

File PE Metadata
Compilation timestamp:
9/28/2015 3:52:44 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x1F1E98

Entry point:
68, AC, A3, B6, 0C, E8, D2, BD, FF, FF, 8B, 45, F4, 0F, B7, 3C, 48, 81, FC, 3D, 5F, A5, 26, 3B, E5, 81, FA, 00, 00, 00, 01, 0F, 83, 2A, 00, 00, 00, 8B, 45, 08, 3B, E1, F9, A8, 56, 3B, 45, FC, 0F, 83, 3C, 27, 12, 00, 0F, B6, 18, C1, E6, 08, F8, C1, E2, 08, 0B, F3, 40, 66, F7, C3, D5, 7A, 89, 45, 08, 12, E7, D3, F0, 8B, C2, C1, E8, 0B, 66, 81, FC, 7D, 45, 0F, AF, C7, F9, 3B, F0, 0F, 83, 77, FF, 15, 00, 8B, D0, F5, 03, C9, E9, 88, FF, 15, 00, 91, 28, 95, AE, 76, E3, EA, DD, 32, 0E, E4, 46, 02, 19, 10, 1D, 54...
 
[+]

Code size:
1.5 MB (1,548,288 bytes)

Remove overlord+vostfr_10924_i64984711_il345.exe - Powered by Reason Core Security