american whore story xxx...sexcat.exe

Asper

Maxiget Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application american whore story xxx...sexcat.exe by Maxiget Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from files-download-109.com.
Publisher:
C Vital  (signed by Maxiget Limited)

Product:
Asper

Description:
LeaveLoadLoud

Version:
4, 10, 25, 0

MD5:
cf05327e2462e06116233f66d4c29351

SHA-1:
6a5b70e028197723fd5f6b75e3b526e65ccda96c

SHA-256:
f4d04da7da5245a359e4f0bd32b36474032257d13b04393dc0f2679c867a3b29

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This is a modified installer version of the software and bundles additional offers including adware.

Analysis date:
11/23/2024 8:23:49 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.New IT Limited (M)
16.8.2.17

File size:
57 KB (58,320 bytes)

Product version:
4, 10, 25, 0

Copyright:
Conical (c)

Trademarks:
TM2-15

Original file name:
lltmoping.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\american whore story xxx...sexcat.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
12/11/2014 2:36:00 PM

Valid to:
8/15/2016 9:41:32 AM

Subject:
CN=Maxiget Limited, O=Maxiget Limited, L=Limassol, S=Cyprus, C=CY

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B83CBF523FA3B

File PE Metadata
Compilation timestamp:
2/26/2015 7:37:03 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:2a3i61W4IBzBQzhdtmWF5MIN6VSJyU4DIeLVjG5oGPp0A:5FbkzByhqWCSJeIeRkoGPpN

Entry address:
0x5167

Entry point:
55, 8B, EC, 83, EC, 44, 56, FF, 15, 54, 60, 40, 00, 8B, F0, 8A, 06, 3C, 22, 74, 10, 3C, 20, 7E, 1E, 46, 80, 3E, 20, 7F, FA, EB, 16, 3C, 22, 74, 11, 46, 8A, 06, 84, C0, 75, F5, 3C, 22, 75, 07, EB, 04, 3C, 20, 7F, 07, 46, 8A, 06, 84, C0, 75, F5, 83, 65, E8, 00, 8D, 45, BC, 50, FF, 15, 30, 60, 40, 00, E8, 5B, 00, 00, 00, 68, 04, 80, 40, 00, 68, 00, 80, 40, 00, E8, 32, 00, 00, 00, F6, 45, E8, 01, 59, 59, 74, 06, 0F, B7, 45, EC, EB, 03, 6A, 0A, 58, 50, 56, 6A, 00, 6A, 00, FF, 15, 2C, 60, 40, 00, 50, E8, B7, FC...
 
[+]

Entropy:
5.5700

Developed / compiled with:
Microsoft Visual C++

Code size:
17 KB (17,408 bytes)

The file american whore story xxx...sexcat.exe has been seen being distributed by the following URL.

Remove american whore story xxx...sexcat.exe - Powered by Reason Core Security