เที่ยงคืน15นาที.exe

New IT Limited

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application เที่ยงคืน15นาที.exe by New IT Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the New IT Desktop Setup installer. The file has been seen being downloaded from dc100.4shared.com.
Publisher:
New IT Limited  (signed and verified)

MD5:
0c35d26ffc39ed1591763027c7c0bf6b

SHA-1:
ae3c8706936a2f8d52e07cc21d6bde9bd5632bca

SHA-256:
66a80a0565248c4234aaf6ea448253f18983243adf65541caaef23b3997b0953

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/28/2024 2:26:45 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.New IT Limited.NewIT.Bundler (M)
16.7.12.11

File size:
10.3 MB (10,769,264 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
New IT Desktop Setup

Common path:
C:\users\{user}\downloads\เที่ยงคืน15นาที.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
11/17/2012 12:16:05 AM

Valid to:
11/16/2013 10:30:34 PM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B2A165690BBAA

File PE Metadata
Compilation timestamp:
1/29/2013 9:16:47 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:X01rsNPt3bE/T3Qs6PGd8Gu1XFeVp8x7v0I5NBv/DZEx7I+liFH3GXRccAaAkhrq:X0eT+T3ll2XFeA5v3NWs0iFHceRaAkSx

Entry address:
0x903D

Entry point:
E8, 8C, 43, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3...
 
[+]

Entropy:
7.9914  (probably packed)

Code size:
85.5 KB (87,552 bytes)

The file เที่ยงคืน15นาที.exe has been seen being distributed by the following URL.