triviasetup_982822500_400612_2843.exe

Amazecell LTD.

The component is part of the TMRG platform which will track various behaviors of web browsing habits including tracking sites and domains visited as well as ads clicked. The application triviasetup_982822500_400612_2843.exe by Amazecell has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer.
Publisher:
Amazecell LTD.  (signed and verified)

MD5:
fd906f0fe282f7ef955f37553d1fa3f1

SHA-1:
bf2bb54a83609faa9a3546410e4a779380b9d1a4

SHA-256:
ba77dac47d9b828f2b4dca38f322238d8f9e3a039c3ca4b4d8fbbffc902e0fee

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 4:50:05 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.TMRG.Amazecel.Installer (M)
16.4.25.1

File size:
512.8 KB (525,080 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\triviasetup_982822500_400612_2843.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
10/30/2012 1:00:00 AM

Valid to:
10/31/2013 12:59:59 AM

Subject:
CN=Amazecell LTD., O=Amazecell LTD., L=Hertzlia, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
365C7458F9CB8CF4C99A5AB69879EFCC

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:UH9gZJJoJmwDy6YTlrj0eFrggMlwcdr0zAlZGD6hOSJJo6:UH9gpokRNxNObdzlZGOOEo6

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove triviasetup_982822500_400612_2843.exe - Powered by Reason Core Security