!sketchytimes_downloader-qanruza7c.exe

Mocal

This is the Somoto BetterInstaller, an installer that bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application !sketchytimes_downloader-qanruza7c.exe by Mocal has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the Somoto BetterInstaller installer. Includes the Somoto BetterInstaller, an adware installer that will bundle offers for additional third party applications, mostly adware toolbars, with legitimate softare and may be installed without adequate user consent.
Publisher:
Mocal  (signed and verified)

MD5:
3a185a83167230f5a39d6611167ac880

SHA-1:
fa9b5db1a673ccc36d8f2f69ac83cf8ef6a5bd80

SHA-256:
a1356d70fd926aa396cc0c6008f63473116374e00f2e602ff7f472a07bcc61fd

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Uses the Somoto 'BetterInstaller' to bundle additional (unwanted) software during install without adequate consent.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/7/2024 7:43:55 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Somoto.Gen
7.11.193.198

AVG
Generic
2015.0.3249

Clam AntiVirus
Win.Adware.Somoto
0.98/21511

ESET NOD32
Win32/Somoto
8.10849

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.2738

McAfee
Artemis!3A185A831672
5600.6905

NANO AntiVirus
Riskware.Win32.Downware.digcac
0.28.6.63850

Panda Antivirus
Trj/Chgt.L
14.12.26.09

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Mocal.c
14.12.26.8

Sophos
Somoto BetterInstaller
4.98

SUPERAntiSpyware
PUP.Somoto/Variant
10154

Trend Micro House Call
Suspicious_GEN.F47V1118
7.2.360

VIPRE Antivirus
Trojan.Win32.Generic
35572

File size:
291.2 KB (298,184 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Somoto BetterInstaller

Common path:
C:\users\{user}\downloads\!sketchytimes_downloader-qanruza7c.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/10/2014 2:00:00 AM

Valid to:
6/11/2015 1:59:59 AM

Subject:
CN=Mocal, O=Mocal, STREET=Bendstr. 18, L=Aachen, S=NRW, PostalCode=52066, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0765B6A8C03E3F98B22046A6D2373518

File PE Metadata
Compilation timestamp:
12/17/2010 10:14:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
6144:iA0m3D0o3/+5BBqrJP97NevCIbDy6jVGw/NTvQsU7XFUBZTqK8m:iA0iD0o344sOYUw/hvQd7XFUBZmK8m

Entry address:
0x39AC

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, 7C, 01, 00, 00, E8, 97, 46, 00, 00, 83, EC, 0C, 68, 01, 80, 00, 00, E8, 42, 43, 00, 00, 6A, 00, E8, AB, 46, 00, 00, 6A, 08, A3, 88, 4C, 42, 00, E8, B1, 28, 00, 00, 6A, 00, 68, 60, 01, 00, 00, A3, 38, 4D, 42, 00, 8D, 85, 90, FE, FF, FF, 50, 6A, 00, 68, A4, A2, 40, 00, E8, F0, 45, 00, 00, 83, EC, 0C, 68, A5, A2, 40, 00, 68, 68, 4D, 42, 00, E8, EF, 2A, 00, 00, 83, C4, 18, E8, FE, 42, 00, 00, 52, 52, 50, 68, 00, D0, 42, 00, E8, DA, 2A, 00, 00, 57, 6A, 00, E8, 39, 42, 00, 00, 83...
 
[+]

Code size:
28.5 KB (29,184 bytes)

The file !sketchytimes_downloader-qanruza7c.exe has been seen being distributed by the following URL.

Remove !sketchytimes_downloader-qanruza7c.exe - Powered by Reason Core Security