do_application_start.exe

Cat Lady Interactive

The application do_application_start.exe has been detected as a potentially unwanted program by 6 anti-malware scanners. This is a setup program which is used to install the application. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from intva1.bitdesktop.com and multiple other hosts.
Publisher:
Cat Lady Interactive

Product:
Cat Lady Interactive

Version:
1.2.9.2183

MD5:
1a60ff98dd1c9e1cf41085f38c76cffb

SHA-1:
1f7aed3d3e72e350827423b916a11bb229f63e57

SHA-256:
970b6ae3c7b92ce32b036fa6d09ef72be66613294f87e493fa6a92da23523e25

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 12:19:53 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SwizBased-gen [Trj]
160326-0

Emsisoft Anti-Malware
Gen:Variant.Razy.19119
11.5.0.6191

ESET NOD32
Win32/DownloadAdmin.Q potentially unwanted application
8.0.319.0

F-Secure
Variant.Application.Bundler
5.15.96

Norman
Gen:Variant.Application.Bundler.DownloadAdmin.9
02.04.2016 17:35:19

Reason Heuristics
Adware.CatLady.Bundler.Installer.Meta (M)
16.4.25.13

File size:
884.5 KB (905,760 bytes)

Product version:
1.2.9.2183

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\do_application_start.exe

File PE Metadata
Compilation timestamp:
5/26/2015 2:37:43 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:YJK+OOHe9J5TUfzdCk3C56Ya/ZJ4JKNomX8THdFz3S:efgJ5wEUjj5NRF

Entry address:
0x4E66

Entry point:
E8, E5, 93, 00, 00, E9, F1, 8C, 00, 00, FF, 25, 34, AB, 4A, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, 18, AA, 4A, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8A, 44, 24, 04, 53, 55, 8B, 6C, 24, 14, 83, C5, 01, 56, 8B, 74, 24, 14, 88, 44, 2E, FF, 57, 0F, 84, CE, 00, 00, 00, 8B, 7C, 24, 24, B3, 0A, 8A, 0E, 0F, B6, D1, 0F, B6, 82, 60, B3, 4A, 00, 83, E8, 01, 74, 5E, 83, E8, 01, 74, 4F, 83, E8, 01, 74, 1D, 8D, 87, 0C, 02, 00, 00, 39, 07, 72, 36, 57, E8, 12, FA, FF, FF, 8B, 0F, 8A, 16, 83, C4, 04, 88...
 
[+]

Entropy:
7.9653  (probably packed)

Code size:
56.5 KB (57,856 bytes)

The file do_application_start.exe has been seen being distributed by the following 50 URLs.

http://intva1.bitdesktop.com/dl-pure?&usefilename=true&hashstring=jbswswsswl41216&signature_id=0&_action_=getbin&filename=minecraftfreedownloadsuscom-setup-127613201 (1).exe&checksum=164352

http://intva1.bitdesktop.com/dl-pure?&usefilename=true&hashstring=jbaprl4182016&signature_id=0&_action_=getbin&filename=openofficesuite-setup-40593579 (1).exe&checksum=165463

http://intva2.clientmulti.com/dl-pure?&usefilename=true&hashstring=jb3252016&signature_id=0&_action_=getbin&filename=Super Mario Sunshine-96187087.exe&checksum=130068

http://intva2.clientmulti.com/dl-pure?&usefilename=true&hashstring=jb3252016&signature_id=0&_action_=getbin&filename=Yu-Gi-Oh! - Reshef Of Destruction-98742003.exe&checksum=130068

http://intva1.bitdesktop.com/dl-pure?&usefilename=true&hashstring=jbswswsswl41216&signature_id=0&_action_=getbin&filename=minecraftfreedownloadsuscom-setup-129568735.exe&checksum=164352

http://intva1.bitdesktop.com/dl-pure?&usefilename=true&hashstring=jbaprl4182016&signature_id=0&_action_=getbin&filename=openofficesuite-setup-41529099.exe&checksum=165463

Latest 30 of 67 download URLs

Remove do_application_start.exe - Powered by Reason Core Security