download.queen.40leipzig.radio.symphony.orchestra41...bohemian.rhapsody.40fl.torrent...kickasstorren

Installer

Amonetize ltd.

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file download.queen.40leipzig.radio.symphony.orchestra41...bohemian.rhapsody.40fl.torrent...kickasstorren by Amonetize ltd has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the Amonetize Downloader installer. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup.
Publisher:
Amônétízé Ltd  (signed by Amonetize ltd.)

Product:
Installer

Version:
1.1.1.20

MD5:
a344d0d1ea02dc465438c50de640fb5a

SHA-1:
6b13d25bcb795629720e11580c47df0deb210dc3

SHA-256:
5c543c77004b69619520fc57fab552afc9da02d26b9400e25e55d7aa3f05d5eb

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/24/2024 11:44:07 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Amonetiz
2014.02.03

avast!
Win32:Amonetize-E [PUP]
2014.9-140203

Dr.Web
Adware.Downware.1655
9.0.1.034

ESET NOD32
Win32/Amonetize.AD (variant)
8.9373

Fortinet FortiGate
Riskware/Amonetize
2/3/2014

Malwarebytes
PUP.Optional.InstallMonetizer
v2014.02.03.06

McAfee
Adware-Amonetize!A344D0D1EA02
5600.7231

Reason Heuristics
PUP.Installer.Amonetizeltd.?
14.8.7.20

Sophos
Amonetize
4.97

Trend Micro House Call
TROJ_GEN.F47V0202
7.2.34

VIPRE Antivirus
Amonetize
26088

File size:
332 KB (340,008 bytes)

Product version:
2.1.12

Copyright:
(c) Amônétízé Ltd, 2012,2013. All rights reserved.

Original file name:
Installer.exe

Bundler/Installer:
Amonetize Downloader

Language:
English (United States)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/18/2013 9:00:00 AM

Valid to:
6/18/2015 8:59:59 AM

Subject:
CN=Amonetize ltd., O=Amonetize ltd., L=Raanana, S=Alberta, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
235E7B2F1D4E0152189F6381E2BA8C97

File PE Metadata
Compilation timestamp:
2/2/2014 9:36:02 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:IN8Lw5kuYVOrhHIebijBAem4tQZeNsIsjEb02ro8GPPhChXmppfB:INmw5WVOrhIebitAeOZ6sjZ2MJP5CAp5

Entry address:
0x275C4

Entry point:
E8, 9A, 95, 00, 00, E9, 89, FE, FF, FF, 57, 8B, C6, 83, E0, 0F, 85, C0, 0F, 85, C1, 00, 00, 00, 8B, D1, 83, E1, 7F, C1, EA, 07, 74, 65, EB, 06, 8D, 9B, 00, 00, 00, 00, 66, 0F, 6F, 06, 66, 0F, 6F, 4E, 10, 66, 0F, 6F, 56, 20, 66, 0F, 6F, 5E, 30, 66, 0F, 7F, 07, 66, 0F, 7F, 4F, 10, 66, 0F, 7F, 57, 20, 66, 0F, 7F, 5F, 30, 66, 0F, 6F, 66, 40, 66, 0F, 6F, 6E, 50, 66, 0F, 6F, 76, 60, 66, 0F, 6F, 7E, 70, 66, 0F, 7F, 67, 40, 66, 0F, 7F, 6F, 50, 66, 0F, 7F, 77, 60, 66, 0F, 7F, 7F, 70, 8D, B6, 80, 00, 00, 00, 8D, BF...
 
[+]

Code size:
231.5 KB (237,056 bytes)

The file download.queen.40leipzig.radio.symphony.orchestra41...bohemian.rhapsody.40fl.torrent...kickasstorren has been seen being distributed by the following 38 URLs.

http://download.getlinksinaseconds.com/.../get.php?q=American.Hustle.2013.DVDSCR.x264.AC3-FooKaS.mkv.flv.flv&ti1=500000&ti2=1&ti3=2014-02-03T12:24:51.498108 00:00

http://download.getlinksinaseconds.com/.../get.php?q={kis keys2014.rar}&ti1=1475000&ti2=0&ti3=2014-02-04T00:17:19.005958 00:00

http://download.venturedownload.com/.../get.php?q=Pockie_Ninja_Hack_Pack.exe&ti1=1405000&ti2=3&ti3=2014-02-02T18:17:05.464525 00:00

Latest 30 of 38 download URLs

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to server-54-230-202-13.fra50.r.cloudfront.net  (54.230.202.13:80)