steam wallet hack v1.1 beta by mhacks.net.exe.exe

M417 LTD.

The application steam wallet hack v1.1 beta by mhacks.net.exe.exe by M417 has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup.
Publisher:
M417 LTD.  (signed and verified)

MD5:
c98895a46417fe2193c7c35a65fffea9

SHA-1:
88ad852fbad03d5e3a11ff2253a0cd166010511c

SHA-256:
56bc50ea8d829b8d26b594bdb91c82f49a0ae7fdb49e2a2e6503165e3644637d

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
4/28/2024 11:35:30 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

avast!
Adware-gen [Adw]
140908-2

Dr.Web
Adware.Downware.2719
9.0.1.05190

K7 AntiVirus
Unwanted-Program
13.183.13476

Panda Antivirus
Trj/InstallMonetizer.A
14.09.24.09

Reason Heuristics
PUP.M417.h
14.9.24.20

Sophos
SpeedyShare Downloader
4.98

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

File size:
97.9 KB (100,256 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\steam wallet hack v1.1 beta by mhacks.net.exe.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
8/12/2013 8:14:35 AM

Valid to:
8/12/2015 5:35:02 PM

Subject:
E=INFO@M417LTD.NET, CN=M417 LTD., O=M417 LTD., L=London, S=Greater London, C=GB, Description=Q1G5XvtHln8BTB3V

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
0AB5

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:kLXB65939tY6HBg4sXJ/JaURJ7s+2dRd20zCj/LnV8g9F3u8lzAk7AgTGI:kLk395hYXJ/t1s+2dT0n/9NlzZ8I

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.1631

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)