download birdman a inesperada virtude da ignorncia dublado e legendado.exe

GENCO LABS LLC

The application download birdman a inesperada virtude da ignorncia dublado e legendado.exe by GENCO LABS has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from www.requestnget.co.
Publisher:
J5TLPO0AaUCQB  (signed by GENCO LABS LLC)

Version:
2.9.3.2

MD5:
97527521cf9fe9cd7ced43d56ba40075

SHA-1:
f05366990d620b22f25adb96ce700a856ebada25

SHA-256:
03afc1a6384b80185703ec8efc3edd3e4dc6dd973817cde4acac18837aa0e0b3

Scanner detections:
12 / 68

Status:
Adware

Analysis date:
12/25/2024 2:09:51 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Adware/Win32.Adload
2015.02.26

Avira AntiVirus
TR/Dldr.Adload.71880.1226
7.11.212.140

avast!
Adware-RE [PUP]
2014.9-150314

AVG
Downloader
2016.0.3170

ESET NOD32
NSIS/TrojanDownloader.Adload.AM trojan
9.7.0.302.0

Fortinet FortiGate
W32/Adload.AM!tr.dldr
3/14/2015

K7 AntiVirus
Unwanted-Program
13.200.15159

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
14.0.0.2346

nProtect
Trojan-Downloader/W32.Agent.71880
15.02.25.01

Reason Heuristics
PUP.Installer.BR Software
15.3.20.19

VIPRE Antivirus
Threat.4150696
37788

File size:
70.2 KB (71,880 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\download birdman a inesperada virtude da ignorncia dublado e legendado.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
2/17/2015 8:53:38 AM

Valid to:
10/20/2015 7:14:36 PM

Subject:
CN=GENCO LABS LLC, O=GENCO LABS LLC, L=Lewes, S=Delaware, C=US

Issuer:
SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00BE2471032696C220

File PE Metadata
Compilation timestamp:
12/5/2009 8:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:eQpQ5EP0ijnRTXJS5qTkBkQ7GUldH66g8cY0vKSNdHgxUUh:eQIURTXJS5GkB1GUlc6RcY0ycu9h

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file download birdman a inesperada virtude da ignorncia dublado e legendado.exe has been seen being distributed by the following URL.