silentinstaller_dotnet2.exe

avtest

The application silentinstaller_dotnet2.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from d29uy4fuda37fc.cloudfront.net.
Product:
avtest

Version:
1.0.0.0

MD5:
ed3118a9cd105a852e7b0d265cbb30c5

SHA-1:
b698695a24907d9135135a2206f4f5e79b7c51c1

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
5/20/2024 3:02:53 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2998918
373

AegisLab AV Signature
Adware.Msil.Imali!c
2.1.4+

Avira AntiVirus
ADWARE/Imali.314368
8.3.2.4

Arcabit
Trojan.Generic.D2DC286
1.0.0.646

Bitdefender
Trojan.GenericKD.2998918
1.0.20.135

Emsisoft Anti-Malware
Trojan.GenericKD.2998918
8.16.01.27.09

ESET NOD32
MSIL/Adware.Imali (variant)
10.12922

Fortinet FortiGate
Adware/Imali
1/27/2016

F-Secure
Trojan.GenericKD.2998918
11.2016-27-01_4

G Data
Trojan.GenericKD.2998918
16.1.25

IKARUS anti.virus
AdWare.MSIL.Imali
t3scan.2.0.3.0

K7 AntiVirus
Adware
13.212.18526

Kaspersky
not-a-virus:HEUR:AdWare.MSIL.Imali
14.0.0.750

MicroWorld eScan
Trojan.GenericKD.2998918
17.0.0.81

NANO AntiVirus
Riskware.Win32.Imali.dzsuhy
1.0.14.5380

nProtect
Trojan.GenericKD.2998918
16.01.25.01

Panda Antivirus
Generic Suspicious
16.01.27.09

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1077

Sophos
Generic PUA LG (PUA)
4.98

File size:
307 KB (314,368 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
avtest_dotnet2.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\silentinstaller_dotnet2.exe

File PE Metadata
Compilation timestamp:
12/13/2015 2:16:50 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:+ZFZT8qbTR7SquD4L8vioH/X8i9DLnHWcefjVo8bS5VO6vIgOjL:KZwgVxGq86oH/MKvnolg2gi

Entry address:
0x4D91E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8807

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
302.5 KB (309,760 bytes)

The file silentinstaller_dotnet2.exe has been seen being distributed by the following URL.

Remove silentinstaller_dotnet2.exe - Powered by Reason Core Security