do_application_start.exe

Cat Lady Interactive

The application do_application_start.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from intva1.bitdesktop.com and multiple other hosts.
Publisher:
Cat Lady Interactive

Product:
Cat Lady Interactive

Version:
1.2.9.2183

MD5:
1fc3c88af90cffeae6b086caf17af926

SHA-1:
3d9c854c1936d64066b42be91e1c9b048fb0b696

SHA-256:
7627ae41f0842341beb09f6cf8e15b084b0f1eb083b9fdb465b92f6ade394f15

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 2:02:12 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.CatLady.Bundler.Installer.Meta (M)
16.5.10.14

File size:
884 KB (905,216 bytes)

Product version:
1.2.9.2183

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\do_application_start.exe

File PE Metadata
Compilation timestamp:
4/19/2015 4:40:52 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:NeY5DEsNEXkP4t65xnYUEcPOb6HMZK4X1DRa1afOKTx:N2sckPy6p/PbMZzhRa0GKt

Entry address:
0x5106

Entry point:
E8, 65, 90, 00, 00, E9, 6B, 89, 00, 00, 56, 8B, 74, 24, 08, 57, 8B, 3D, 40, F0, 40, 00, 68, 14, 50, 4B, 00, 56, 89, 35, 10, 40, 4C, 00, FF, D7, A3, 60, 40, 4C, 00, 85, C0, 75, 18, C7, 05, 14, 40, 4C, 00, 14, 50, 4B, 00, FF, 15, 3C, F0, 40, 00, 5F, A3, 18, 40, 4C, 00, 5E, C3, 68, 2A, 50, 4B, 00, 56, FF, D7, A3, D0, 40, 4C, 00, 85, C0, 75, 18, C7, 05, 14, 40, 4C, 00, 2A, 50, 4B, 00, FF, 15, 3C, F0, 40, 00, 5F, A3, 18, 40, 4C, 00, 5E, C3, 68, 3C, 50, 4B, 00, 56, FF, D7, A3, BC, 40, 4C, 00, 85, C0, 75, 18, C7...
 
[+]

Code size:
56 KB (57,344 bytes)

The file do_application_start.exe has been seen being distributed by the following 9 URLs.

http://intva1.bitdesktop.com/dl-pure?&usefilename=true&hashstring=jbswswsswl41216&signature_id=0&_action_=getbin&filename=minecraftfreedownloadsuscom-setup-133069083.exe&checksum=164352

http://intva2.clientmulti.com/dl-pure?&usefilename=true&signature_id=0&_action_=getbin&filename=Pokemon_ Ruby Version (V1.2)-133018229.exe&checksum=168600

http://intva2.clientmulti.com/dl-pure?&usefilename=true&signature_id=0&_action_=getbin&filename=Super Mario 64-133018639.exe&checksum=168600

Remove do_application_start.exe - Powered by Reason Core Security