adblockie_1.1.exe

Adblock IE

MGTEK

This is a self-extracting archive and installer. The file has been seen being downloaded from a334.http.cdn.softlayer.net and multiple other hosts.
Publisher:
MGTEK  (signed and verified)

Product:
Adblock IE

Description:
Adblock IE Installer

Version:
1.0.488.0

MD5:
eb847c980822fb5bce60761bd70cd9a6

SHA-1:
61805813751b475d960618bb8616b544d09a3423

SHA-256:
d378b8aac6a2216f673f840beaa6510efcd7b8b2ee2bfb9ac56d26e02ea323e8

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/5/2024 7:00:16 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Keylogger
1.3.0.4959

File size:
944.8 KB (967,512 bytes)

Product version:
1.0.488.0

Copyright:
© 2010-2011 MGTEK. All rights reserved.

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
MGTEK

Valid from:
1/1/2011 12:00:00 AM

Valid to:
12/31/2011 12:00:00 AM

Subject:
CN=MGTEK, O=MGTEK, C=DE

Issuer:
CN=MGTEK Root Authority, O=MGTEK, C=DE

Serial number:
D3ADD5B8644C1389437C186CD7A56FE1

File PE Metadata
Compilation timestamp:
12/26/2011 8:48:29 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:O0n8EUb73b3SUujmXrVa7Ws/4VPL8wBx7ITDka:7n8/Pb3SUPXZa7Z4VPL8wBx7I

Entry address:
0xB7E6

Entry point:
E8, 57, 67, 00, 00, E9, 78, FE, FF, FF, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 00, 01, 00, 00, 72, 0E, 83, 3D, 1C, FE, 41, 00, 00, 74, 05, E9, 13, 68, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07, 83, C7, 01, 83, EA, 01, 75, F6, 8B, 44, 24, 08, 5F, C3, 8B...
 
[+]

Code size:
88.5 KB (90,624 bytes)

The file adblockie_1.1.exe has been seen being distributed by the following 2 URLs.

http://a334.http.cdn.softlayer.net/00A334/.../adblockie_1.1.exe

Scan adblockie_1.1.exe - Powered by Reason Core Security