اوبريت صباح محمود وضياء الحميد وماهر احم....exe

New IT Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application اوبريت صباح محمود وضياء الحميد وماهر احم....exe by New IT Limited has been detected as adware by 17 anti-malware scanners. The file has been seen being downloaded from 4sd.getafilefree.net.
Publisher:
New IT Limited  (signed and verified)

Version:
3, 3, 50, 0

MD5:
ab829727a917670b48ac3bac170a42f9

SHA-1:
142e89ad9e058a6bc61b7260f6c27bc8a3ed5a21

SHA-256:
cf19cc3aa0fdd4c494aa8da113a039ee47bfee8172cd4f16df97624fe68a9a5f

Scanner detections:
17 / 68

Status:
Adware

Analysis date:
1/13/2025 10:44:39 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.4Shared
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.171.22

AVG
Generic
2015.0.3359

Comodo Security
Application.Win32.4Shared.K
19440

Dr.Web
Adware.Downware.2538
9.0.1.05190

ESET NOD32
Win32/4Shared.U potentially unwanted application
7.0.302.0

F-Prot
W32/A-bff17ff2
v6.4.7.1.166

G Data
Win32.Application.4shared
14.9.24

IKARUS anti.virus
PUA.4Shared
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.183.13286

Malwarebytes
PUP.Optional.4Shared
v2014.09.06.11

McAfee
Obfosha
5600.7015

NANO AntiVirus
Riskware.Win32.Downware.ddvrsd
0.28.2.61942

Panda Antivirus
Trj/Genetic.gen
14.09.06.11

Reason Heuristics
PUP.NewITLimited.i
14.9.6.13

Vba32 AntiVirus
Downloader.GetFaster
3.12.26.3

VIPRE Antivirus
Threat.4150696
32210

File size:
408 KB (417,840 bytes)

Product version:
3, 3, 50, 0

Copyright:
2014

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\?????? ???? ????? ????? ?????? ????? ???....exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
5/14/2014 3:00:04 PM

Valid to:
12/30/2016 10:33:53 AM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
049768F7F19C91

File PE Metadata
Compilation timestamp:
7/30/2014 1:20:06 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:irXm17vhZg5CFSSF1rU5Z1c0V5+EjGCj/d+GpYjJQNvGtBu3YOno:EW1Lhm/SF9U5gs5+yljl+Gyj+5GtBu3

Entry address:
0x2BC8B

Entry point:
E8, F6, A3, 00, 00, E9, 78, FE, FF, FF, CC, 8B, FF, 55, 8B, EC, 83, EC, 14, A1, B8, ED, 44, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 57, 8B, F1, 39, 1D, 04, 06, 45, 00, 75, 38, 53, 53, 33, FF, 47, 57, 68, 94, 3F, 44, 00, 68, 00, 01, 00, 00, 53, FF, 15, 60, 11, 44, 00, 85, C0, 74, 08, 89, 3D, 04, 06, 45, 00, EB, 15, FF, 15, E4, 10, 44, 00, 83, F8, 78, 75, 0A, C7, 05, 04, 06, 45, 00, 02, 00, 00, 00, 39, 5D, 14, 7E, 22, 8B, 4D, 14, 8B, 45, 10, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, 45, 14, 2B...
 
[+]

Entropy:
6.7521

Code size:
255 KB (261,120 bytes)

The file اوبريت صباح محمود وضياء الحميد وماهر احم....exe has been seen being distributed by the following URL.