yamaha+motif+xs8+replacem_10924_i129637020_il345.exe

AITI Strim CONSULTING, TOV

The application yamaha+motif+xs8+replacem_10924_i129637020_il345.exe by AITI Strim CONSULTING, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
AITI Strim CONSULTING, TOV  (signed and verified)

MD5:
6927542f398b98fd611d7c4bc3cbce70

SHA-1:
d53e02d7b0b7a425f4250fce6f7c47c4038407e2

SHA-256:
a65e59c052ff0f68f9cd4a61ec672eca48b6da31078f39bf39e00decccb6cec0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 4:17:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize.AITIStri (M)
16.7.3.1

File size:
2 MB (2,132,824 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\yamaha+motif+xs8+replacem_10924_i129637020_il345.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/11/2016 3:00:00 AM

Valid to:
1/11/2017 2:59:59 AM

Subject:
CN="AITI Strim CONSULTING, TOV", OU=IT, O="AITI Strim CONSULTING, TOV", STREET="Bud. 53-55, vul.Pochainynska", L=Kyyiv, S=Kyyiv, PostalCode=04080, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5A7A1CB365BD8EA3567456D3B8166630

File PE Metadata
Compilation timestamp:
1/25/2016 3:02:53 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:oR0mdUje9kLQRbbhomL8hqHKWPa2EKNb42I9QRVH3:MlUjaNGPQqU/mQRVH3

Entry address:
0x35B6D6

Entry point:
68, 92, 96, 57, 3D, E8, 44, BC, F3, FF, 12, F9, 7E, 59, 3C, F6, 35, D8, 06, BF, 02, EE, 63, 68, 21, D9, 28, F7, 0C, DB, 13, B7, D4, 1C, B5, F2, 7D, 23, 3E, BE, 75, 40, 78, 6A, 09, 8A, DF, 05, 7D, CD, 75, C0, 19, CA, AB, 75, C0, 60, F3, 82, 8A, BF, 30, 38, E4, 8A, 5F, AC, EE, 74, 75, 40, 70, EE, FE, 8A, 3F, 68, 85, AB, 8A, FF, 89, D5, 76, 98, 0D, 0B, 75, 40, 63, 4B, 8A, 1F, 2D, CA, C7, 75, E0, AA, 8C, D0, 75, A0, 66, 62, 64, 8A, 7F, A4, FD, 59, 8A, 1F, 86, 94, EE, 75, 20, EF, 4B, 2D, 8A, 3F, F8, F9, F7, 34...
 
[+]

Entropy:
7.9810  (probably packed)

Code size:
2 MB (2,122,240 bytes)