transformers_prime_french_torrent_saison_1_complet_downloader.exe

Holy app

Infra Delta Inc. LTD

The application transformers_prime_french_torrent_saison_1_complet_downloader.exe by Infra Delta has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from us.springfile.org.
Publisher:
Infra Delta Inc. LTD  (signed and verified)

Product:
Holy app

Description:
The Holy binary

Version:
1, 0, 1206, 1

MD5:
167c3cb2b2ec2d8c0d00445a070842de

SHA-1:
446b51d38fdff7f5231955ae60a810cccf1eb922

SHA-256:
4da0be0a7f52edbd4326e3275ec324cde6725c463bcc37b9d3eea51b1f9089ba

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/3/2024 3:06:56 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Amonetize (M)
16.8.10.1

File size:
4.3 MB (4,537,576 bytes)

Product version:
9.0.2.1

Copyright:
© 2008 - 2016 Holy

Original file name:
Holy.exe

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\users\{user}\downloads\transformers_prime_french_torrent_saison_1_complet_downloader.exe

Digital Signature
Authority:
Infra Delta Inc. LTD

Valid from:
8/5/2016 7:59:57 PM

Valid to:
8/5/2017 7:59:57 PM

Subject:
CN=Infra Delta Inc., OU=Infra Delta Inc., O=Infra Delta Inc. LTD, S=London, C=UK

Issuer:
CN=Infra Delta Inc., C=UK, S=London, L=London, E=admin@infradelta.co, OU=Infra Delta Inc., O=Infra Delta Inc. LTD

Serial number:
100001

File PE Metadata
Compilation timestamp:
8/5/2016 6:17:58 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
98304:Qh/3axrfw9iYKeBZ+LkgqsnfPkjWYCr1ZkYBAbFTRUVnDaa1d:uvaxzwukgjn3kj7eBAbbUVDaa1d

Entry address:
0x1462B1

Entry point:
E8, F5, 04, 00, 00, E9, 8E, FE, FF, FF, 55, 8B, EC, FF, 75, 08, E8, 67, FC, FF, FF, 59, 5D, C3, FF, 25, 7C, 43, 5B, 00, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 2A, 06, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 14, 06, 00, 00, CC, CC, CC, CC, 80, F9, 40, 73, 15, 80, F9, 20, 73, 06, 0F, A5, C2, D3, E0, C3, 8B, D0, 33, C0, 80, E1, 1F, D3, E2, C3, 33, C0, 33, D2, C3, CC, 80, F9, 40, 73, 15, 80, F9, 20, 73, 06, 0F, AD, D0, D3, EA, C3, 8B...
 
[+]

Code size:
1.7 MB (1,780,736 bytes)

The file transformers_prime_french_torrent_saison_1_complet_downloader.exe has been seen being distributed by the following URL.