compactmanydownloader.free.9932.exe

ManyDownloader

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application compactmanydownloader.free.9932.exe has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from installer.manydownloader.com.
Publisher:
Visicom Media Inc.

Product:
ManyDownloader

Version:
1.5.3.5

MD5:
7d4768331edf29edd5646084b5425dcf

SHA-1:
3a58886bca793d445003a16d2ee3d61ee8635137

SHA-256:
b44246b597236331103cb7985297b6cd681ff4b52f53ba8467b5f552c27c20f8

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 4:49:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom.VisicomM.Meta (M)
16.7.11.14

File size:
315.9 KB (323,519 bytes)

Product version:
2.0.4.364

Copyright:
Copyright © 1996-2016 Visicom Media Inc.

Trademarks:
ManyDownloader is a trademark of Visicom Media

Original file name:
ManyDownloader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\compactmanydownloader.free.9932.exe

File PE Metadata
Compilation timestamp:
3/8/2016 2:21:27 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:8ZXooUzOx+qaX9LKuApq5bHNlfJFC6zQbrNgBV+UdvrEFp7hKN1Ba:8Zoxzs+hGuAAPe0QfqBjvrEH7k1Ba

Entry address:
0x7D37

Entry point:
E9, D3, 7D, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, 8C, 04, 00, 00, 3B, 0D, 70, A0, 42, 00, 75, 02, F3, C3, E9, 0C, 31, 00, 00, 8B, FF, 55, 8B, EC, 8B, 45, 14, 56, 57, 33, FF, 3B, C7, 74, 47, 39, 7D, 08, 75, 1B, E8, A2, 35, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 8F, 0F, 00, 00, 83, C4, 14, 8B, C6, EB, 29, 39, 7D, 10, 74, E0, 39, 45, 0C, 73, 0E, E8, 7D, 35, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, D7, 50, FF, 75, 10, FF, 75, 08, E8, C1, 31, 00, 00, 83, C4, 0C, 33, C0, 5F, 5E, 5D...
 
[+]

Entropy:
6.9232

Packer / compiler:
Xtreme-Protector v1.05

Code size:
121.5 KB (124,416 bytes)

The file compactmanydownloader.free.9932.exe has been seen being distributed by the following URL.

Remove compactmanydownloader.free.9932.exe - Powered by Reason Core Security