2atitle2a.exe

Internet Explorer

Avanpost IT, TOV

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application 2atitle2a.exe by Avanpost IT, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Microsoft Corporation  (signed by Avanpost IT, TOV)

Product:
Internet Explorer

Version:
11.00.9600.16428 (winblue_gdr.131013-1700)

MD5:
10e5e18d707ea5fd8798422e58c5a8dd

SHA-1:
e260710b7131ea2d8efad3b2be323019c4a81acd

SHA-256:
412e68ca15429f9c2e93a78ec1ce29f07d4563e8d88bcd14d4257cc312abbeea

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 8:25:31 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize (M)
17.2.15.11

File size:
6 MB (6,308,384 bytes)

Product version:
11.00.9600.16428

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
IEXPLORE.EXE.MUI

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\2atitle2a.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/22/2016 4:00:00 AM

Valid to:
3/23/2017 3:59:59 AM

Subject:
CN="Avanpost IT, TOV", OU=IT, O="Avanpost IT, TOV", STREET=Bud. 58 prospekt P'yatdesyatyrichchya Srsr, L=Kharkiv, S=Kharkivska, PostalCode=61000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FD2121F7F1B4A1FB43BF7FCA522878EF

File PE Metadata
Compilation timestamp:
1/14/2013 11:09:53 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

Entry address:
0x5D13AE

Entry point:
E8, 69, 11, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 88, FF, 9D, 00, E8, 0C, 17, 00, 00, E8, 3A, 13, 00, 00, 0F, B7, F0, 6A, 02, E8, FC, 10, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, BB, 08, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
5.9 MB (6,136,832 bytes)

Remove 2atitle2a.exe - Powered by Reason Core Security