360amigoprosetup.exe

360 Amigo System SpeedUp

Business Bakers

The application 360amigoprosetup.exe by Business Bakers has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from 10.1.101.6.
Publisher:
360Amigo  (signed by Business Bakers)

Product:
360 Amigo System SpeedUp

Version:
1.2.1.4500

MD5:
e05ecf090361cbd7fb0029b0b0e8bde7

SHA-1:
4833adaf1036ffd2e57b5886a25adbfb4fa3782c

SHA-256:
27c0386e62274777a81e21b982c0e1aa8fe2fecb2d2eab91c26139e8bb995bfa

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/17/2024 7:28:08 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.6.5.21

File size:
2.7 MB (2,842,696 bytes)

Product version:
1.2

Copyright:
Copyright 2009-2010 by 360Amigo

Trademarks:
360Amigo

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\downloads\360amigoprosetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/30/2010 7:00:00 AM

Valid to:
7/31/2011 6:59:59 AM

Subject:
CN=Business Bakers, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Business Bakers, L=Helsinki, S=Helsinki, C=FI

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
71346AFF5AC5D072DC31F7DC3A872308

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:Jp/ealdN0nMbiH/S3wsywUlfPZWwqk7QlkqKUT25:Jp2alb4aFWZWHOQlkqKSk

Entry address:
0x825001

Entry point:
60, E9, 3D, 04, 00, 00, 49, 85, A5, A1, A1, 4A, A1, 1A, 91, 98, E5, A1, A2, 7C, 8A, 3C, 71, 9E, E5, A1, 22, 1C, 5D, E8, E5, A1, A1, 28, 3C, 5D, E8, E5, A1, AE, 24, C7, A2, A1, A1, 66, 24, 92, 98, E5, A1, A1, A1, A1, A1, 2C, 24, A5, EB, E5, A1, F1, 5E, 34, A1, EA, E5, A1, 28, 24, A1, EB, E5, A1, 2A, 59, 2C, 3C, B0, EB, E5, A1, F2, F1, 5E, 34, 5D, EB, E5, A1, 28, 24, 5D, 9E, E5, A1, 2C, 3C, BF, EB, E5, A1, F2, F6, 5E, 34, 5D, EB, E5, A1, 28, 24, A1, E1, E5, A1, 2C, 24, 14, 98, E5, A1, 5E, 41, D1, 59, B6, A1...
 
[+]

Packer / compiler:
ASPack v2.11

Code size:
1.5 MB (1,567,744 bytes)

The file 360amigoprosetup.exe has been seen being distributed by the following URL.

http://10.1.101.6/C/Software/.../360amigoprosetup.exe

Remove 360amigoprosetup.exe - Powered by Reason Core Security