aphilips1_03.exe

The application aphilips1_03.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from s10057.chomikuj.pl.
MD5:
23d66254d79690089ee2a82beb699400

SHA-1:
ad3fbabe8f177a17a5cbf098fcf146ce53170291

SHA-256:
91bc61ef351782d4f2561d21f8f31a5edb31b9b5986a272c11dbda6048736291

Scanner detections:
12 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
2/25/2025 8:05:09 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.Generic
7.1.1

Avira AntiVirus
TR/Agent.143872.9
7.11.100.92

avast!
Win32:Malware-gen
2014.9-160319

Bitdefender
Adware.Generic.418704
1.0.20.395

Dr.Web
Adware.InstallCore.53
9.0.1.079

Emsisoft Anti-Malware
Adware.Generic.418704
8.16.03.19.12

G Data
Adware.Generic.418704
16.3.22

MicroWorld eScan
Adware.Generic.418704
17.0.0.237

Norman
Suspicious_Gen4.CFAMZ
11.20160319

Trend Micro House Call
TROJ_GEN.RCBH1B4
7.2.79

Trend Micro
PAK_Generic.001
10.465.19

VIPRE Antivirus
Adware.Trojan.Win32.Generic
21158

File size:
140.5 KB (143,872 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\aphilips1_03.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:tSyztb8YkXdAFMfGwtvyO7tM2oCsvEQJfYNMkr:YBewlomsvECf

Entry address:
0x61001

Entry point:
60, E8, 03, 00, 00, 00, E9, EB, 04, 5D, 45, 55, C3, E8, 01, 00, 00, 00, EB, 5D, BB, ED, FF, FF, FF, 03, DD, 81, EB, 00, 10, 06, 00, 83, BD, 22, 04, 00, 00, 00, 89, 9D, 22, 04, 00, 00, 0F, 85, 65, 03, 00, 00, 8D, 85, 2E, 04, 00, 00, 50, FF, 95, 4D, 0F, 00, 00, 89, 85, 26, 04, 00, 00, 8B, F8, 8D, 5D, 5E, 53, 50, FF, 95, 49, 0F, 00, 00, 89, 85, 4D, 05, 00, 00, 8D, 5D, 6B, 53, 57, FF, 95, 49, 0F, 00, 00, 89, 85, 51, 05, 00, 00, 8D, 45, 77, FF, E0, 56, 69, 72, 74, 75, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 56, 69, 72...
 
[+]

Packer / compiler:
ASPack v2.12

Code size:
282 KB (288,768 bytes)

The file aphilips1_03.exe has been seen being distributed by the following URL.

Remove aphilips1_03.exe - Powered by Reason Core Security