garena shell hack v2 0 downloader__3687_i1916492020_il373998.exe

Smart Inst

PLT

The application garena shell hack v2 0 downloader__3687_i1916492020_il373998.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from www.markersoffredefy.site.
Publisher:
PLT

Product:
Smart Inst

Description:
tiny install

Version:
39.162.37.68

MD5:
fa65a49bdb62cc3af0d4980eb9752af3

SHA-1:
7e3b1046262bea4bd09a15f20bddb9e19e3edf58

SHA-256:
d4cf2562fcc1d1636cafa00fffa61c588123a208931464b09bd92651538c67c0

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
6/29/2025 11:21:19 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Amonetize-KC [PUP]
160327-1

Emsisoft Anti-Malware
Gen:Application.Imonetize
11.5.0.6191

ESET NOD32
Win32/Amonetize.TV potentially unwanted application
8.0.319.0

Kaspersky
not-a-virus:Downloader.Win32.AdLoad
15.0.0.562

McAfee
Program.PUP-RHEI
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.219.1166.0

Norman
Gen:Application.Imonetize.2
10.04.2016 15:29:17

Reason Heuristics
PUP.InstallMonetizer.PLT.Installer.Meta (M)
16.5.9.12

File size:
569 KB (582,656 bytes)

Product version:
39.162.37.68

Copyright:
Rights 2000

Trademarks:
Trd Mark

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\garena shell hack v2 0 downloader__3687_i1916492020_il373998.exe

File PE Metadata
Compilation timestamp:
5/6/2016 6:24:27 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:5VsSqNRz5mmKZaKh1CueHjH02LGfGlC7V7VmS:BqNRz5/KZaKh18DU2LGAavZ

Entry address:
0x7A44

Entry point:
E8, 19, 37, 00, 00, E9, 8C, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2B, FF, 75, 08, 6A, 00, FF, 35, 70, 26, 41, 00, E9, 9F, EE, FF, FF, 85, C0, 75, 17, 56, E8, EF, 23, 00, 00, 8B, F0, E9, 9B, 23, 00, 00, 50, E8, A0, 23, 00, 00, 59, 89, 06, 5E, 5D, C3, CC, CC, CC, CC, CC, 80, F9, 40, 73, 15, 80, F9, 20, 73, 06, 0F, AD, D0, D3, EA, C3, 8B, C2, 33, D2, 80, E1, 1F, D3, E8, C3, 33, C0, 33, D2, C3, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73, 08, 33, 35, 80, 10, 41, 00, 57, 8B, 06...
 
[+]

Code size:
47.5 KB (48,640 bytes)

The file garena shell hack v2 0 downloader__3687_i1916492020_il373998.exe has been seen being distributed by the following URL.