descargar links protegidos__3038_i1306542808_il3185271.exe

Ukra-2006 LLC

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application descargar links protegidos__3038_i1306542808_il3185271.exe by Ukra-2006 has been detected as adware by 37 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Ukra-2006 LLC  (signed and verified)

Version:
1.1.8.22

MD5:
dd2fdc017f6523d419b25d6f3bb770f6

SHA-1:
426a1e621bfdc53a436bcfae91cbbbfbd884cbff

SHA-256:
7a77600835d23d72ca26af208a0ad68400c07f12e096cb948db28310678962bf

Scanner detections:
37 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/27/2024 4:37:21 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Virtob.Gen.12
867

Agnitum Outpost
Win32.Virut.AB.Gen
7.1.1

AhnLab V3 Security
Win32/Virut.F
2014.09.17

Avira AntiVirus
ADWARE/Adware.Gen
7.11.171.244

avast!
Win32:Vitro
2014.9-140921

AVG
Ukra
2015.0.3345

Bitdefender
Win32.Virtob.Gen.12
1.0.20.1320

Bkav FE
W32.Vetor.PE
1.3.0.4959

Dr.Web
Win32.Virut.56
9.0.1.0264

Emsisoft Anti-Malware
Win32.Virtob.Gen.12
8.14.09.21.10

ESET NOD32
Win32/Virut.NBP virus
8.7.0.302.0

Fortinet FortiGate
W32/FakeAV.RQ!tr
9/21/2014

F-Prot
W32/Virut.E.gen
v6.4.6.5.141

F-Secure
Win32.Virtob.Gen.12
11.2014-21-09_1

G Data
Win32.Virtob.Gen.12
14.9.24

K7 AntiVirus
Virus
13.183.13393

Kaspersky
Virus.Win32.Virut
14.0.0.3218

Malwarebytes
PUP.Optional.Amonetize
v2014.09.21.05

McAfee
Artemis!DD2FDC017F65
5600.7001

Microsoft Security Essentials
Threat.Undefined
1.185.155.0

MicroWorld eScan
Win32.Virtob.Gen.12
15.0.0.792

NANO AntiVirus
Virus.Win32.Virut.hpeg
0.28.2.62151

Norman
Virut.HL
11.20140921

nProtect
Virus/W32.Virut.Gen
14.09.17.01

Panda Antivirus
W32/Sality.AO
14.09.21.10

Qihoo 360 Security
Virus.Win32.Virut.O
1.0.0.1015

Quick Heal
W32.Virut.G
9.14.14.00

Reason Heuristics
PUP.Installer.Ukra2006.w
14.9.21.5

Rising Antivirus
PE:Win32.Virut.cx!1553679
23.00.65.14919

Sophos
Amonetize
4.98

Total Defense
Win32/Virut.17408
37.0.11184

Trend Micro House Call
PE_VIRUX.S-3
7.2.264

Trend Micro
PE_VIRUX.S-3
10.465.21

Vba32 AntiVirus
Virus.Virut.14
3.12.26.3

VIPRE Antivirus
Threat.4120919
32938

ViRobot
Win32.Virut.AM
2011.4.7.4223

Zillya! Antivirus
Virus.Virut.Win32.1939
2.0.0.1925

File size:
404.2 KB (413,904 bytes)

Product version:
1.1.8.22

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Language:
English (United States)

Common path:
C:\users\{user}\downloads\descargar links protegidos__3038_i1306542808_il3185271.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/1/2014 2:00:00 AM

Valid to:
7/2/2015 1:59:59 AM

Subject:
CN=Ukra-2006 LLC, O=Ukra-2006 LLC, L=Kharkiv, S=Harkivska obl, C=UA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2B3200D1AF3CAC4253C00F000EF4BAB9

File PE Metadata
Compilation timestamp:
9/10/2014 4:59:43 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:ga5Mqqub6lskGCEurlTA2xhDUy/l6vbDRhFpsNzhsxcJd2+2x:pMqp6ikqgRpxhvXHsxc72+k

Entry address:
0x17610

Entry point:
E8, 8B, 84, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 3D, 94, AF, 3C, 00, 00, 75, 18, E8, A9, 7D, 00, 00, 6A, 1E, E8, F3, 7B, 00, 00, 68, FF, 00, 00, 00, E8, C3, F4, FF, FF, 59, 59, 8B, 45, 08, 85, C0, 75, 01, 40, 50, 6A, 00, FF, 35, 94, AF, 3C, 00, FF, 15, 60, 21, 3C, 00, 5D, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 94, AF, 3C, 00, 00, 75, 18, E8, 5F, 7D, 00, 00, 6A, 1E, E8, A9, 7B, 00, 00, 68, FF, 00, 00, 00, E8, 79, F4, FF, FF, 59, 59, 85, DB, 74, 04, 8B, C3...
 
[+]

Code size:
192.5 KB (197,120 bytes)

The file descargar links protegidos__3038_i1306542808_il3185271.exe has been seen being distributed by the following 3 URLs.

http://www-squid.cluster11.fb-hosting-apps.com/download.php?version=1.1.8.22&campid=3038&instid[appname]=wwe 2012 playstation 2_Downloader&instid[appsetupurl]=http://go.edgydownload.com/getfast/download.cgi?9&ti1=1405000&ti2=0&ti3=DD1_2014-09-14T11:56:47.857589+00:00&instid[cmdline]=/S /PERFORMINSTALL /NORUN&instid[appimageurl]=http://download.edgydownload.com/d1/logo150x150.png&prefix=wwe 2012 playstation 2&instid[thankyoupage]=http://download.edgydownload.com/.../thank_you.php?ti1=1405000&ti2=0&ti3=DD1_2014-09-14T11:56:47.857589+00:00&parameter=wwe 2012 playstation 2&instid[interrupted]=http://download.edgydownload.com/.../interrupted.php?ti1=1405000&ti2=0&ti3=DD1_2014-09-14T11:56:47.857589+00:00&parameter=wwe 2012 playstation 2&ti1=1405000&ti2=0&ti3=DD1_2014-09-14T11:56:47.857589 00:00