christmas_shopper_simulator_2__black_friday-1.0-93594909_-93594909.exe

Cat Lady Interactive

The application christmas_shopper_simulator_2__black_friday-1.0-93594909_-93594909.exe has been detected as a potentially unwanted program by 5 anti-malware scanners. This is a setup program which is used to install the application. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from intva1.bitdesktop.com and multiple other hosts.
Publisher:
Cat Lady Interactive

Product:
Cat Lady Interactive

Version:
1.2.9.2183

MD5:
4d6cdd76f0c81698e4ec8104ed6a665b

SHA-1:
b0a8c0d0d237bf1646b107af88737214e72a6779

SHA-256:
79493d621c2a09131ed146aa183b3a7f3537f4f44cb677f2fdd08790a2cd65ac

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 1:53:40 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160327-1

Emsisoft Anti-Malware
Gen:Variant.Razy.19119
11.5.0.6191

ESET NOD32
Win32/DownloadAdmin.Q potentially unwanted application
8.0.319.0

F-Secure
Variant.Application.Bundler
5.15.96

Norman
Gen:Variant.Application.Bundler.DownloadAdmin.9
10.04.2016 15:29:17

File size:
885.7 KB (906,912 bytes)

Product version:
1.2.9.2183

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\christmas_shopper_simulator_2__black_friday-1.0-93594909_-93594909.exe

File PE Metadata
Compilation timestamp:
5/8/2015 1:36:38 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:WLuz3c0M7GtVyCFLOZA2z2j8k/ea5OUAyo/9fuM:UkiKPyCFa24ie7fyo/9fX

Entry address:
0x50C6

Entry point:
E8, 75, 94, 00, 00, E9, 9F, 8C, 00, 00, FF, 25, 48, 14, 4B, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 01, 50, FF, 15, 1C, 01, 41, 00, C3, CC, CC, CC, CC, CC, CC, 56, 8B, F1, 8B, 46, 0C, 57, 8B, 3D, 18, 01, 41, 00, 50, FF, D7, 8B, 4E, 08, 51, FF, D7, 8B, 56, 04, 52, FF, D7, 5F, 5E, C3, CC, 8A, 01, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 04, 56, 6A, 00, 68, 80, 00, 00, 00, 6A, 03, 6A, 00, 6A, 07, 68, 00, 00, 00, 80, 50, 8B, F1, FF, 15, 08, 01, 41, 00, 89, 46, 08, 83, F8, FF...
 
[+]

Code size:
57 KB (58,368 bytes)

The file christmas_shopper_simulator_2__black_friday-1.0-93594909_-93594909.exe has been seen being distributed by the following 18 URLs.

http://intva1.bitdesktop.com/dl-pure?&usefilename=true&hashstring=jbswswsswl41216&signature_id=0&_action_=getbin&filename=minecraftfreedownloadsuscom-setup-42901019.exe&checksum=164352

http://intva1.bitdesktop.com/dl-pure?&usefilename=true&hashstring=jbaprl4182016&signature_id=0&_action_=getbin&filename=openofficesuite-setup-40291111.exe&checksum=150539