xpadder+2015+retail+multi_10924_i90815198_il345.exe

MP4 Downloader Pro

KASHTAN OOO

The application xpadder+2015+retail+multi_10924_i90815198_il345.exe, “MP4 Downloader Pro Setup ” by KASHTAN OOO has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Tomabo   (signed by KASHTAN OOO)

Product:
MP4 Downloader Pro

Description:
MP4 Downloader Pro Setup

MD5:
3db6a0ccdc1124895621590521c345b3

SHA-1:
2716d6e8682d698d7ab50afce542c050f2e1c684

SHA-256:
e5d37392356f05d167439a2d82d97349b89926bb8f67a2dca079312b53680547

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 12:15:57 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Win32/DH{PXIx?}
2016.0.2913

Bkav FE
W32.HfsAdware
1.3.0.7383

Dr.Web
Trojan.Amonetize.11197
9.0.1.0331

ESET NOD32
Win32/Amonetize.LM potentially unwanted (variant)
9.12631

NANO AntiVirus
Trojan.Win32.Amonetize.dytuks
0.30.26.4751

Qihoo 360 Security
HEUR/QVM19.1.Malware.Gen
1.0.0.1077

Reason Heuristics
PUP.KASHTAN.Installer (M)
15.11.27.5

Vba32 AntiVirus
Signed-Downware.Amonetize
3.12.26.4

File size:
3.3 MB (3,466,640 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/4/2015 7:00:00 PM

Valid to:
5/21/2016 6:59:59 PM

Subject:
CN=KASHTAN OOO, O=KASHTAN OOO, L=Naberezhnye Chelny, S=Tatarstan republic, C=RU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
468BE39F7FCABE2D4D2D070862DD916B

File PE Metadata
Compilation timestamp:
11/26/2015 6:12:48 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
98304:fdAeb1ieuZSo2lzYhl5E827miAhJ4yrJjX3vJNd4fB:fdAeb1ieJo0Yhl5E17miAgyrdX3vJNdA

Entry address:
0x32B287

Entry point:
68, 86, 57, A0, D6, E8, A3, 72, FF, FF, 4B, 65, 77, 6A, 2B, EE, 7E, 79, 7B, 41, 3B, E1, 48, 4F, 4A, 7D, 43, 56, 20, F5, 73, 46, 73, 5F, 26, EE, 4C, 23, DE, 7C, 49, 56, 10, CD, 57, FF, FF, FF, FF, 62, 98, 74, 00, CC, 09, 74, 00, FF, FF, FF, FF, 5B, 15, 74, 00, 55, 18, 73, 00, FF, FF, FF, FF, 0F, DC, 74, 00, 2D, 6E, 73, 00, 8D, 1C, 13, 4A, F9, 8B, 55, F8, 81, FC, F3, 58, 6E, 58, E9, 2A, 24, 01, 00, 4D, 67, 66, 46, 37, EB, 65, 73, 71, 48, 36, D2, 43, 2C, E1, 7C, 49, 5C, 0C, C0, 57, 3B, F9, 85, DD, 0B, F7, 0F...
 
[+]

Code size:
2.9 MB (3,021,824 bytes)