reason core security 1 0 8 wit downloader__3687_i1767340043_il955617.ace

The file reason core security 1 0 8 wit downloader__3687_i1767340043_il955617.ace has been detected as a potentially unwanted program by 7 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from www.xm8off.info.
MD5:
b6f9bad70c23746446bc2fc62f27dab3

SHA-1:
eb3d428eb357317a86364b507b6ce7b61a4f3c2e

SHA-256:
9c051abc0a94561e829c6816c57a626f92b3c34f1a12a3f66f86cb244cc2cc70

Scanner detections:
7 / 68

Status:
Potentially unwanted

Analysis date:
5/30/2025 7:22:54 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Jaik.9671
5691597

Dr.Web
infected with Trojan.Amonetize.11548
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Jaik.9671
10.0.0.5366

ESET NOD32
Win32/Amonetize.LY potentially unwanted application
7.0.302.0

Kaspersky
not-a-virus:Downloader.Win32.AdLoad
15.0.0.562

Norman
Gen:Variant.Jaik.9671
07.10.2015 03:16:12

Reason Heuristics
PUP.Amonetize (M)
16.1.6.22

File size:
731.3 KB (748,821 bytes)

Common path:
C:\users\{user}\downloads\reason core security 1 0 8 wit downloader__3687_i1767340043_il955617.ace

The file reason core security 1 0 8 wit downloader__3687_i1767340043_il955617.ace has been seen being distributed by the following URL.