sam__2268_il21277.exe

Install Path Ltd

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application sam__2268_il21277.exe by Install Path has been detected as adware by 18 anti-malware scanners. The program is a setup application that uses the Amonetize Downloader installer. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Install Path Ltd  (signed and verified)

Version:
1.1.5.26

MD5:
17486817e8c0160050bdc99ae145961c

SHA-1:
aafedad2c859f8bfff28201c0d382b7d40982705

SHA-256:
59d4155d7d4bf74a783e2c4f9791181a6ca1b97d0f0f6303b54ba2fe808c5c69

Scanner detections:
18 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 1:05:56 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Jatif.103
711

Avira AntiVirus
ADWARE/Adware.Gen2
7.11.212.80

avast!
Win32:Malware-gen
2014.9-150224

AVG
Amonetize
2016.0.3184

Baidu Antivirus
Adware.Win32.Amonetize
4.0.3.15224

Bitdefender
Gen:Variant.Application.Jatif.103
1.0.20.275

Dr.Web
Trojan.Amonetize.797
9.0.1.060

ESET NOD32
Win32/Amonetize.DU potentially unwanted (variant)
9.11224

Fortinet FortiGate
Riskware/Amonetize
2/24/2015

F-Secure
Gen:Variant.Application.Jatif
11.2015-24-02_3

G Data
Gen:Variant.Application.Jatif.103
15.2.25

K7 AntiVirus
Unwanted-Program
13.198.15062

McAfee
Artemis!17486817E8C0
5600.6845

MicroWorld eScan
Gen:Variant.Application.Jatif.103
16.0.0.165

Panda Antivirus
PUP/MultiToolbar.A
15.03.01.01

Reason Heuristics
PUP.Installer.Amonetize
15.2.24.7

Sophos
Amonetize
4.98

VIPRE Antivirus
Trojan.Win32.Generic
37902

File size:
631.1 KB (646,216 bytes)

Product version:
1.1.5.26

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Amonetize Downloader

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\sam__2268_il21277.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
1/19/2015 10:00:00 PM

Valid to:
1/20/2016 9:59:59 PM

Subject:
CN=Install Path Ltd, O=Install Path Ltd, L=Ramat Gan, S=Israel, C=IL

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
0F41500997F5154087C4C8A76EF53F6C

File PE Metadata
Compilation timestamp:
2/24/2015 5:03:16 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:eoRY0JBApbgFzWLt+ZoowRiYYwL9NusC7V7+m4ZXrN:8MzzWZ+6+wL9N9aIZZXB

Entry address:
0x2FD2B

Entry point:
E8, 76, F6, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 10, A1, C0, 2A, 47, 00, 33, C5, 89, 45, FC, 8B, 55, 18, 53, 33, DB, 56, 57, 3B, D3, 7E, 1F, 8B, 45, 14, 8B, CA, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, C2, 2B, C1, 48, 3B, C2, 7D, 01, 40, 89, 45, 18, 89, 5D, F8, 39, 5D, 24, 75, 0B, 8B, 45, 08, 8B, 00, 8B, 40, 04, 89, 45, 24, 8B, 35, 6C, 90, 45, 00, 33, C0, 39, 5D, 28, 53, 53, FF, 75, 18, 0F, 95, C0, FF, 75, 14, 8D, 04, C5, 01, 00, 00, 00, 50, FF, 75, 24, FF, D6, 8B, F8, 89...
 
[+]

Code size:
351 KB (359,424 bytes)

The file sam__2268_il21277.exe has been seen being distributed by the following 11 URLs.

q=http://goo.gl/n3CbmG&redir_token=Hps7IroUAgW3Og40NtlPko7ns1p8MTQyNTE0OTg2OEAxNDI1MDYzNDY4

Remove sam__2268_il21277.exe - Powered by Reason Core Security