أعمال الميزانية.exe

SuperCharging

New IT Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application أعمال الميزانية.exe by New IT Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from ds322.getafilefast.net.
Publisher:
SPC LLC  (signed by New IT Limited)

Product:
SuperCharging

Description:
DWD

Version:
3, 3, 29, 0

MD5:
74ec7c4ddec40e53af787027c512c9e3

SHA-1:
7ea1f3d1fd014b1de65ad8fe2211e1a62f9a020e

SHA-256:
74baac06f4131efe3ae3021776209b9c4f87b68180fc8b03a2db911e1126c87a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 11:24:16 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.New IT Limited (M)
16.7.28.13

File size:
391.6 KB (401,016 bytes)

Product version:
3, 3, 29, 0

Copyright:
2013

Trademarks:
-

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\أعمال الميزانية.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
5/14/2014 2:00:04 PM

Valid to:
12/30/2016 9:33:53 AM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
049768F7F19C91

File PE Metadata
Compilation timestamp:
6/12/2014 2:44:54 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:TvJuqTV/4hfJdwNwWyWdxi2GDN6PNqqGHONILXnWYBuLGf1E:rJHVQJ2wWyoi7N6PY1HZWYBuqfe

Entry address:
0x288B4

Entry point:
E8, 93, 91, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 14, A1, 18, AD, 44, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 57, 8B, F1, 39, 1D, 3C, C5, 44, 00, 75, 38, 53, 53, 33, FF, 47, 57, 68, BC, FF, 43, 00, 68, 00, 01, 00, 00, 53, FF, 15, 70, D1, 43, 00, 85, C0, 74, 08, 89, 3D, 3C, C5, 44, 00, EB, 15, FF, 15, B4, D0, 43, 00, 83, F8, 78, 75, 0A, C7, 05, 3C, C5, 44, 00, 02, 00, 00, 00, 39, 5D, 14, 7E, 22, 8B, 4D, 14, 8B, 45, 10, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, 45, 14, 2B, C1...
 
[+]

Entropy:
6.6420

Code size:
237 KB (242,688 bytes)

The file أعمال الميزانية.exe has been seen being distributed by the following URL.

Remove أعمال الميزانية.exe - Powered by Reason Core Security