Setup.exe

Installer

Amonetize ltd.

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file Setup.exe by Amonetize ltd has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the Amonetize Downloader installer. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
Amônétízé Ltd  (signed by Amonetize ltd.)

Product:
Installer

Version:
1.1.5.86

MD5:
c4af061e7ebac347deef580440e5e44e

SHA-1:
c1c7b848dd80e15a65e1370e658fd2a16e7fc59d

SHA-256:
f33eb1adcc10463c7fed25265d8a96f425b6d4253257b61aadd1f176af10e123

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 12:49:15 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.1655
9.0.1.0195

ESET NOD32
Win32/Amonetize.AA (variant)
9.9190

Malwarebytes
PUP.Optional.InstallMonetizer
v2015.07.14.04

McAfee
Artemis!C4AF061E7EBA
5600.6705

Reason Heuristics
PUP.Amonetize.Bundler (M)
15.7.14.4

Sophos
Amonetize
4.96

Trend Micro House Call
TROJ_GEN.F47V1218
7.2.195

VIPRE Antivirus
Amonetize
24540

File size:
394 KB (403,496 bytes)

Product version:
2.1.12

Copyright:
(c) Amônétízé Ltd, 2012,2013. All rights reserved.

Original file name:
Installer.exe

Bundler/Installer:
Amonetize Downloader

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/18/2013 7:30:00 PM

Valid to:
6/18/2015 7:29:59 PM

Subject:
CN=Amonetize ltd., O=Amonetize ltd., L=Raanana, S=Alberta, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
235E7B2F1D4E0152189F6381E2BA8C97

File PE Metadata
Compilation timestamp:
12/18/2013 1:31:09 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:yChYqjn26YuvEEMKzY26jf4DNwzhM6zmJ0ftRrpw/O:BRY/x26C0zmJ0vrpuO

Entry address:
0x26E43

Entry point:
E8, 84, 96, 00, 00, E9, 89, FE, FF, FF, 57, 8B, C6, 83, E0, 0F, 85, C0, 0F, 85, C1, 00, 00, 00, 8B, D1, 83, E1, 7F, C1, EA, 07, 74, 65, EB, 06, 8D, 9B, 00, 00, 00, 00, 66, 0F, 6F, 06, 66, 0F, 6F, 4E, 10, 66, 0F, 6F, 56, 20, 66, 0F, 6F, 5E, 30, 66, 0F, 7F, 07, 66, 0F, 7F, 4F, 10, 66, 0F, 7F, 57, 20, 66, 0F, 7F, 5F, 30, 66, 0F, 6F, 66, 40, 66, 0F, 6F, 6E, 50, 66, 0F, 6F, 76, 60, 66, 0F, 6F, 7E, 70, 66, 0F, 7F, 67, 40, 66, 0F, 7F, 6F, 50, 66, 0F, 7F, 77, 60, 66, 0F, 7F, 7F, 70, 8D, B6, 80, 00, 00, 00, 8D, BF...
 
[+]

Code size:
229.5 KB (235,008 bytes)

The file Setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.soledownload.com  (54.225.181.84:80)

TCP (HTTP):
Connects to www.activemonetizer.com  (23.23.96.46:80)

 
http://www.activemonetizer.com/index.php?Net2=v2.0.50727&Net4=&OSversion=NT5.1SP3&Slv=&Sysid=B224747837&Sysid1=B224747837&X64=N&admin=Y&browser=IEXPLORE.EXE&chver=&exe=ikjut__24531726&offver=&lang_DfltUser=04

Remove Setup.exe - Powered by Reason Core Security