avg8b18.exe

SilentInstaller

The application avg8b18.exe has been detected as a potentially unwanted program by 18 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from d7z6k023fw1k0.cloudfront.net and multiple other hosts.
Product:
SilentInstaller

Version:
1.0.0.1

MD5:
a85df53ac3cdc0b948809c73b39b0571

SHA-1:
ef99016d9d1f9b12aa31c6e14da932e5d7abc250

SHA-256:
467c538847ed7fb4bc771cc8672482dd5b9ea7990622aebea42d68b79fa6bafb

Scanner detections:
18 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 3:15:16 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.MSILPerseus.1128
5818656

AhnLab V3 Security
PUP/Win32.OfferInstaller
2015.12.23

Avira AntiVirus
TR/Dropper.MSIL.Gen
8.3.2.4

Arcabit
Trojan.Adware.MSILPerseus.D468
1.0.0.637

Baidu Antivirus
Adware.MSIL.Imali
4.0.3.151222

Bitdefender
Gen:Variant.Adware.MSILPerseus.1128
1.0.20.1780

Emsisoft Anti-Malware
Gen:Variant.Adware.MSILPerseus.1128
10.0.0.5366

ESET NOD32
MSIL/Adware.Imali.C application
7.0.302.0

F-Secure
Gen:Variant.MSILPerseus.1128
5.15.21

G Data
Gen:Variant.Adware.MSILPerseus.1128
15.12.25

IKARUS anti.virus
AdWare.MSIL.Imali
t3scan.1.9.5.0

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.931

Malwarebytes
PUP.Optional.SilentInstaller
v2015.12.22.09

McAfee
Trojan.Artemis!A85DF53AC3CD
18.0.204.0

MicroWorld eScan
Gen:Variant.Adware.MSILPerseus.1128
16.0.0.1068

Norman
Gen:Variant.Adware.MSILPerseus.1128
17.12.2015 06:34:11

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.151220

SUPERAntiSpyware
Adware.Kazy/Variant
9431

File size:
314 KB (321,536 bytes)

Product version:
1.0.0.1

Copyright:
Copyright © 2014

Original file name:
SilentInstaller_dotnet4.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\avg8b18.exe

File PE Metadata
Compilation timestamp:
12/22/2015 7:32:21 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:hD4FZT8qbTR7SquD4L8vioH/X8i9DLnHWcefjVo8bS5VY5ezunL:hDIZwgVxGq86oH/MKvnolgTuL

Entry address:
0x4F4AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
309.5 KB (316,928 bytes)

The file avg8b18.exe has been seen being distributed by the following 2 URLs.

Remove avg8b18.exe - Powered by Reason Core Security