00000000

Site on Spot Limited

This is the Somoto BetterInstaller, an installer that bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The file 00000000 by Site on Spot Limited has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the Somoto BetterInstaller installer. Includes the Somoto BetterInstaller, an adware installer that will bundle offers for additional third party applications, mostly adware toolbars, with legitimate softare and may be installed without adequate user consent.
Publisher:
Site on Spot Limited  (signed and verified)

Version:
1.0.0.1

MD5:
9e22a874249976a6a20716efd5ac7c41

SHA-1:
9297658b4e1d1cc5b18db59834d8c231acad4e12

SHA-256:
4abf1d94b29bace43687f455ff7bac3be57778feed0d5fc0595b6798088f4f38

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Uses the Somoto 'BetterInstaller' to bundle additional (unwanted) software during install without adequate consent.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/27/2024 1:38:52 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Somoto
4.0.3.15218

Clam AntiVirus
Win.Adware.Somoto
0.98/21511

ESET NOD32
Win32/Somoto.G potentially unwanted
9.11193

NANO AntiVirus
Riskware.Win32.Downware.digcac
0.30.0.126

Panda Antivirus
Trj/Genetic.gen
15.02.18.09

Quick Heal
Adware.NSIS.BetterInstaller.A
2.15.14.00

Reason Heuristics
PUP.Bundler.Somoto
15.5.3.0

VIPRE Antivirus
Trojan.Win32.Generic
37670

File size:
403.6 KB (413,328 bytes)

Bundler/Installer:
Somoto BetterInstaller

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\google\chrome\user data\default\file system\011\t\00\00000000

Digital Signature
Authority:
thawte, Inc.

Valid from:
1/28/2015 5:30:00 AM

Valid to:
7/10/2015 5:29:59 AM

Subject:
CN=Site on Spot Limited, O=Site on Spot Limited, L=Tel Aviv, S=Israel, C=IL

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
477E336D7B42EDDDED42DABF6FAB572F

File PE Metadata
Compilation timestamp:
12/17/2010 2:44:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
6144:VA0m350GwQw6HZ5c4pOi3QuxJUSkia3mMuc4O/sODiBwJcSXJekg0V86UdLIDtFb:VA0i50GwNgOmbY1lvdWxwA0VaLIsdk

Entry address:
0x39AC

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, 7C, 01, 00, 00, E8, 97, 46, 00, 00, 83, EC, 0C, 68, 01, 80, 00, 00, E8, 42, 43, 00, 00, 6A, 00, E8, AB, 46, 00, 00, 6A, 08, A3, 88, 4C, 42, 00, E8, B1, 28, 00, 00, 6A, 00, 68, 60, 01, 00, 00, A3, 38, 4D, 42, 00, 8D, 85, 90, FE, FF, FF, 50, 6A, 00, 68, A4, A2, 40, 00, E8, F0, 45, 00, 00, 83, EC, 0C, 68, A5, A2, 40, 00, 68, 68, 4D, 42, 00, E8, EF, 2A, 00, 00, 83, C4, 18, E8, FE, 42, 00, 00, 52, 52, 50, 68, 00, D0, 42, 00, E8, DA, 2A, 00, 00, 57, 6A, 00, E8, 39, 42, 00, 00, 83...
 
[+]

Entropy:
7.8983  (probably packed)

Code size:
28.5 KB (29,184 bytes)

The file 00000000 has been seen being distributed by the following URL.

Remove 00000000 - Powered by Reason Core Security