thehiddenworld_244191.exe

Goodware

The application thehiddenworld_244191.exe by Goodware has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer.
Publisher:
Goodware  (signed and verified)

Description:
campaign exe

Version:
1.11106.11315.13325

MD5:
6691ae22f5bdbfbe9c57039e1fe1775c

SHA-1:
bc8d4662ae9f6df709b6507aa1cdb9820a66cf18

SHA-256:
bee34f6ae72ca14586469b7328b6d5e0def5f56266a62edfaf95114eec59cef2

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
4/27/2024 2:29:51 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.7940
9.0.1.067

herdProtect (fuzzy)
2015.6.14.19

Malwarebytes
PUP.Optional.Campaign.A
v2015.03.08.02

McAfee
Artemis!6691AE22F5BD
5600.6832

Norman
Downloader
11.20150308

Reason Heuristics
PUP.Installer.Goodware
15.3.8.14

Sophos
Goodware Installer
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Dropper
10010

Trend Micro House Call
TROJ_GEN.R02SH05BE15
7.2.67

VIPRE Antivirus
Adinstaller.Goodware/SmartInstaller
38058

File size:
57.1 KB (58,424 bytes)

Product version:
1.11106.11315.13325

Copyright:
@campaign

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\thehiddenworld_244191.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
6/11/2013 10:48:47 PM

Valid to:
6/7/2014 11:17:21 AM

Subject:
CN=Goodware, O=Goodware, L=Bellevue, S=WA, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
280598DC6499BD

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:3pgpHzb9dZVX9fHMvG0D3XJzBCOf2FcrspFI55:5gXdZt9P6D3XJVCOOCr+C

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.2317

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove thehiddenworld_244191.exe - Powered by Reason Core Security