strikethevbood.rar.exe

Stanislav Kabin

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application strikethevbood.rar.exe by Stanislav Kabin has been detected as adware by 24 anti-malware scanners. This is a setup program which is used to install the application. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
Stanislav Kabin  (signed and verified)

MD5:
6b3adb14b931450c73932f34b359074a

SHA-1:
3879fc1bd67c18068278f91eb3ae1dd8d9c9aae8

SHA-256:
25e5a5cba81e4e8fd2cf1b130b2a95c84be2104f74efbb984e96e633a578e92a

Scanner detections:
24 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
4/26/2024 6:01:40 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.MultiPlug
7.1.1

AhnLab V3 Security
PUP/Win32.MultiPlug
2015.02.16

Avira AntiVirus
Adware/MultiPlug.aoa
7.11.210.60

avast!
Win32:Agent-AUVV [Trj]
150129-1

AVG
Adware Generic5.BENU
2014.0.4257

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Trojan.Multiplug-9
0.98/21511

Comodo Security
Application.Win32.MultiPlug.PNU
21085

Dr.Web
Trojan.Crossrider.28215
9.0.1.05190

ESET NOD32
Win32/AdWare.MultiPlug.BF application
7.0.302.0

F-Prot
W32/A-5958afe0
v6.4.7.1.166

G Data
Win32.Adware.MultiPlug.AC
15.2.25

K7 AntiVirus
Adware
13.194.14969

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
15.0.0.543

Malwarebytes
PUP.Optional.DownloaderSS
v2015.02.15.06

McAfee
Program.MultiPlug
16.8.708.2

NANO AntiVirus
Riskware.Win32.MultiPlug.ddsvpv
0.30.0.65070

nProtect
Trojan-Clicker/W32.MultiPlug.666120
15.02.13.01

Panda Antivirus
PUP/TSUploader
15.02.15.06

Reason Heuristics
PUP.StanislavKabin
15.2.15.6

Sophos
PUA 'MultiPlug' (of type Adware)
5.10

Vba32 AntiVirus
Downware.MultiPlug.gen
3.12.26.3

VIPRE Antivirus
Threat.4150696
36694

Zillya! Antivirus
Adware.MultiPlug.Win32.57
2.0.0.2068

File size:
650.5 KB (666,120 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\strikethevbood.rar.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
6/23/2014 1:28:15 PM

Valid to:
6/23/2015 1:28:15 PM

Subject:
E=Stanislav.Kabin@hotmail.com, CN=Stanislav Kabin, O=Stanislav Kabin, C=RU

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
3469022839E88D596EA6FE14C990AF76

File PE Metadata
Compilation timestamp:
8/6/2014 5:01:25 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:xZVunYav79cKnZxCAgX2QRkOSllkpGF57Lsth6RpoX/wR4u24:zsp9cWZVnQecI7Q+pOEE4

Entry address:
0xC461

Entry point:
E8, 3E, 3C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 10, 9F, 41, 00, E8, 19, 16, 00, 00, E8, 0B, 3E, 00, 00, 0F, B7, F0, 6A, 02, E8, D1, 3B, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, C4, 2C, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
82.5 KB (84,480 bytes)

The file strikethevbood.rar.exe has been seen being distributed by the following URL.

Remove strikethevbood.rar.exe - Powered by Reason Core Security