ch_first_test_2114.exe

The application ch_first_test_2114.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from cdn.riceateastcach.us.
MD5:
82d4a39f2d87cbe85218172bdab37d09

SHA-1:
fac51767bee624e4f0e31361293fa3a39609c372

SHA-256:
ecd00e170c03d7b69d1eb9d3f50ca630b2813ac9f7f69df7a0537f5999d7660c

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
11/27/2024 3:44:55 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallMonetizer.AG potentially unwanted application
8.0.319.0

F-Prot
W32/AdAgent.AI.gen
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.223.2544.0

Reason Heuristics
PUP.InstallMonetizer.ET (M)
16.6.25.10

File size:
335.1 KB (343,131 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\ch_first_test_2114.exe

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:/e34wZQpLG8y59EuWnNIAIxr0LppkZG5S/VeUfQLMpbyZyt5q2pd5A8WW:GZYLG8y0NIV0Fp8Go1Q4paybJd5A8L

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8073

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file ch_first_test_2114.exe has been seen being distributed by the following URL.

Remove ch_first_test_2114.exe - Powered by Reason Core Security