download speedconnect internet accelerator 7.5 full version, mempercepat koneksi internet__5325_il19

Installer

The file download speedconnect internet accelerator 7.5 full version, mempercepat koneksi internet__5325_il19 has been detected as a potentially unwanted program by 18 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from www.amonisto.com and multiple other hosts. While running, it connects to the Internet address www.ibbalance.com on port 443.
Product:
Installer

Version:
1.1.6.20

MD5:
586acef59ecfa98f3b3956af1d82ac5f

SHA-1:
4a53aae26175f575169d2aa4c52afdf178f32b43

SHA-256:
1884744c9a61cc5831e273614eb013e9e9c356c84d11376f076dac23285c6bc3

Scanner detections:
18 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 3:31:52 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.668557
1018

AhnLab V3 Security
PUP/Win32.Amonetiz
2014.01.31

avast!
Win32:Dropper-gen [Drp]
2014.9-140423

AVG
Generic5
2015.0.3496

Baidu Antivirus
Trojan.Win32.Amonetize
4.0.3.14423

Bitdefender
Adware.Generic.668557
1.0.20.565

Dr.Web
Adware.Downware.1833
9.0.1.0113

Emsisoft Anti-Malware
Adware.Generic.668557
8.14.04.23.10

ESET NOD32
Win32/Amonetize.AA (variant)
8.9360

Fortinet FortiGate
Riskware/Amonetize
4/23/2014

F-Secure
Adware.Generic.668557
11.2014-23-04_4

G Data
Adware.Generic.668557
14.4.24

K7 AntiVirus
Trojan
13.175.11021

Malwarebytes
PUP.Optional.Amonetize
v2014.04.23.10

McAfee
Adware-Amonetize!586ACEF59ECF
5600.7152

MicroWorld eScan
Adware.Generic.668557
15.0.0.339

Panda Antivirus
Generic Malware
14.04.23.10

VIPRE Antivirus
Trojan.Win32.Generic
25988

File size:
324 KB (331,776 bytes)

Product version:
2.1.12

Copyright:
(c) 2012,2013. All rights reserved.

Original file name:
Installer.exe

Language:
English (United States)

Common path:
C:\users\{user}\downloads\download speedconnect internet accelerator 7.5 full version, mempercepat koneksi internet__5325_il1927943.exe

File PE Metadata
Compilation timestamp:
1/14/2014 12:14:10 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:iVvmBltODBbYXch9LigjBedOTpn3ey1/9usn3uspheLtt/3S0l/pY:iVuBlEDwcTLigtedA7uUXphemEpY

Entry address:
0x26EC3

Entry point:
E8, 74, 96, 00, 00, E9, 89, FE, FF, FF, 57, 8B, C6, 83, E0, 0F, 85, C0, 0F, 85, C1, 00, 00, 00, 8B, D1, 83, E1, 7F, C1, EA, 07, 74, 65, EB, 06, 8D, 9B, 00, 00, 00, 00, 66, 0F, 6F, 06, 66, 0F, 6F, 4E, 10, 66, 0F, 6F, 56, 20, 66, 0F, 6F, 5E, 30, 66, 0F, 7F, 07, 66, 0F, 7F, 4F, 10, 66, 0F, 7F, 57, 20, 66, 0F, 7F, 5F, 30, 66, 0F, 6F, 66, 40, 66, 0F, 6F, 6E, 50, 66, 0F, 6F, 76, 60, 66, 0F, 6F, 7E, 70, 66, 0F, 7F, 67, 40, 66, 0F, 7F, 6F, 50, 66, 0F, 7F, 77, 60, 66, 0F, 7F, 7F, 70, 8D, B6, 80, 00, 00, 00, 8D, BF...
 
[+]

Entropy:
6.4253

Code size:
229.5 KB (235,008 bytes)

The file download speedconnect internet accelerator 7.5 full version, mempercepat koneksi internet__5325_il19 has been seen being distributed by the following 2 URLs.

http://www.amonisto.com/download.php?version=1.1.6.20&campid=4607&capp=FlashPlayer&prefix=Yevadu.by.movierulz.com.avi&ti1=MTU3fDg4MHxJTnwzfDF8fGEyVjVkMjl5WkEqV1dWMllXUjFMbUo1TG0xdmRtbGxjblZzZWk1amIyMHVZWFpw|8479f585dd2ff4e1f4ae6fb327ba89b1

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)