หนึ่งเดียวคือแม่ เพลงประกอบละคร ทองเนื้อ....exe

Filegetter

New IT Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application หนึ่งเดียวคือแม่ เพลงประกอบละคร ทองเนื้อ....exe, “Helps file downloading” by New IT Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from 4sd.getafilefast.net.
Publisher:
Company limited  (signed by New IT Limited)

Product:
Filegetter

Description:
Helps file downloading

Version:
3, 3, 40, 0

MD5:
e3b30cc66061c143b71cd42ac91eaee2

SHA-1:
0d934cef95c2fb7b759844671bb5e97ffbe18a9f

SHA-256:
7f77dd2183955b20d1bbba695f1bac283aac2ccbf48294a1e5f43232477f1476

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
1/13/2025 4:41:26 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.New IT Limited.NewIT (M)
16.2.26.13

File size:
385.7 KB (394,992 bytes)

Product version:
3, 3, 40, 0

Copyright:
2014

Trademarks:
Company(C)

Original file name:
FilegetterInstrumnet

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\หนึ่งเดียวคือแม่ เพลงประกอบละคร ทองเนื้อ....exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
5/14/2014 7:00:04 PM

Valid to:
12/30/2016 2:33:53 PM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
049768F7F19C91

File PE Metadata
Compilation timestamp:
7/3/2014 7:09:23 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:TTfMcpR8Zhdv/8kqcZI7U1K3EbY5m50HfPVTJ16pBuK:XfMcf851TZI7UQ3EbYg50H3Bf6pBuK

Entry address:
0x2B30B

Entry point:
E8, FD, A3, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 14, A1, A8, ED, 44, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 57, 8B, F1, 39, 1D, 04, 06, 45, 00, 75, 38, 53, 53, 33, FF, 47, 57, 68, 60, 3E, 44, 00, 68, 00, 01, 00, 00, 53, FF, 15, 50, 11, 44, 00, 85, C0, 74, 08, 89, 3D, 04, 06, 45, 00, EB, 15, FF, 15, CC, 10, 44, 00, 83, F8, 78, 75, 0A, C7, 05, 04, 06, 45, 00, 02, 00, 00, 00, 39, 5D, 14, 7E, 22, 8B, 4D, 14, 8B, 45, 10, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, 45, 14, 2B, C1...
 
[+]

Entropy:
6.6473

Code size:
252.5 KB (258,560 bytes)

The file หนึ่งเดียวคือแม่ เพลงประกอบละคร ทองเนื้อ....exe has been seen being distributed by the following URL.