chip_'n_dale's_rescue_rangers-131013553-131013553.exe

Cat Lady Interactive

The application chip_'n_dale's_rescue_rangers-131013553-131013553.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from intva2.clientmulti.com and multiple other hosts.
Publisher:
Cat Lady Interactive

Product:
Cat Lady Interactive

Version:
1.2.9.2183

MD5:
844af184dcfdeadb0f81336073546d69

SHA-1:
8b4587b25b1b42ce3293c1e559b80159235c46b9

SHA-256:
2a3e754f3368a5eb149efc25e130791a0fac80d9997333d31cdae7e46db14c0d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 5:03:38 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.CatLady.Bundler.Installer.Meta (M)
16.5.3.16

File size:
888.2 KB (909,472 bytes)

Product version:
1.2.9.2183

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\chip_'n_dale's_rescue_rangers-131013553-131013553.exe

File PE Metadata
Compilation timestamp:
4/5/2015 11:21:23 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:vVSTnm3aIDGajRMzh5oHIfgg9oqHn4eB:v0TnsDPHIBeqH4k

Entry address:
0x4FA6

Entry point:
E8, 05, 93, 00, 00, E9, 0F, 8C, 00, 00, FF, 25, 00, 3F, 4C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, 48, 46, 4C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, 24, 3F, 4C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 0C, 8A, 4C, 24, 04, 56, 8B, 74, 24, 0C, 88, 0C, 06, 8A, 0E, 40, 80, F9, 0D, 0F, 84, BA, 00, 00, 00, 80, F9, 3D, 74, 3C, 80, F9, 09, 74, 12, 80, F9, 1F, 0F, 86, C2, 00, 00, 00, 80, F9, 7F, 0F, 83, B9, 00, 00, 00, 57, 8B, 7C, 24, 18, 8D, 97, 0C, 02, 00, 00, 39, 17, 72...
 
[+]

Code size:
56.5 KB (57,856 bytes)

The file chip_'n_dale's_rescue_rangers-131013553-131013553.exe has been seen being distributed by the following 13 URLs.

http://intva2.clientmulti.com/dl-pure?&usefilename=true&hashstring=jb3252016&signature_id=0&_action_=getbin&filename=Super Mario Advance 4 - Super Mario Bros. 3 (V1.1)-131225973.exe&checksum=130068