barcelona.vs.real.valladolid.exe

Downloader Helper

Maxiget Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application barcelona.vs.real.valladolid.exe by Maxiget Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from www.adshost2.com.
Publisher:
Maxiget Limited  (signed and verified)

Product:
Downloader Helper

Version:
3, 0, 15, 0

MD5:
9852e86ec006fca723c922877d8e84e1

SHA-1:
2fea6d468f88f104c015aaf840fd05167b7f2448

SHA-256:
501632ed947a0e53085e9b74164237d97693c132b526ecf9d1adfc8f7d65c990

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This is a modified installer version of the software and bundles additional offers including adware.

Analysis date:
11/23/2024 12:45:41 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.New IT Limited (M)
16.8.10.14

File size:
279.3 KB (285,984 bytes)

Product version:
3, 0, 15, 0

Copyright:
Copyright (C) 2013

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\barcelona.vs.real.valladolid.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
8/15/2013 9:41:32 AM

Valid to:
8/15/2016 9:41:32 AM

Subject:
CN=Maxiget Limited, O=Maxiget Limited, L=Limassol, S=Cyprus, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
045BA815265145

File PE Metadata
Compilation timestamp:
10/8/2013 8:35:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:t7QbdpgvwOt5waIy1g5oKbhjkU3ZMppppppppplppppppppppjd1Is111111111f:tMrUwOUaIx5luCMppppppppplppppppF

Entry address:
0x19144

Entry point:
E8, 4E, 6A, 00, 00, E9, 78, FE, FF, FF, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D, 41, FE, 8B, 4C, 24, 04...
 
[+]

Entropy:
6.8640

Code size:
155.5 KB (159,232 bytes)

The file barcelona.vs.real.valladolid.exe has been seen being distributed by the following URL.

Remove barcelona.vs.real.valladolid.exe - Powered by Reason Core Security