download__15022_i1613125325_il540816.exe.rar

The file download__15022_i1613125325_il540816.exe.rar has been detected as a potentially unwanted program by 23 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from websitedhoome.com.
MD5:
6e8250741c8f1c7baca2d1e517f1f665

SHA-1:
a1bf9ecc5cbea06dce2afb76f6533d69f1836b3f

SHA-256:
a5e0405a87281de554ccc3687de9c4fbd869d22e342f405c28a20e5010e4df7b

Scanner detections:
23 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 2:13:33 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Amonetize.BG
5722465

Avira AntiVirus
ADWARE/Amonetize.Gen
8.3.2.2

Arcabit
Application.Bundler.Amonetize.BG
1.0.0.567

AVG
Generic_r
2016.0.2973

Baidu Antivirus
PUA.Win32.Amonetize
4.0.3.15928

Bitdefender
Application.Bundler.Amonetize.BG
1.0.20.1355

Comodo Security
Application.Win32.Amonetize.HD
23315

Dr.Web
infected with Trojan.Amonetize.6636
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.Amonetize.BG
10.0.0.5366

ESET NOD32
Win32/Amonetize.HO potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/Amonetize
9/28/2015

F-Prot
W32/Amonetize.R.gen
v6.4.7.1.166

F-Secure
Application.Bundler.Amonetize
11.2015-28-09_2

G Data
Application.Bundler.Amonetize.BG
15.9.25

IKARUS anti.virus
AdWare.Amonetize
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.210.17345

McAfee
Program.Artemis!83C5EFFE4BE7
18.0.204.0

MicroWorld eScan
Application.Bundler.Amonetize.BG
16.0.0.813

NANO AntiVirus
Trojan.Win32.Amonetize.dxafne
0.30.26.3725

Norman
Application.Bundler.Amonetize.BG
04.08.2015 10:30:46

Qihoo 360 Security
Win32/Virus.Adware.8c5
1.0.0.1015

Sophos
Generic PUA LD (PUA)
4.98

VIPRE Antivirus
Trojan.Win32.Generic
44116

File size:
678.6 KB (694,924 bytes)

Common path:
C:\users\{user}\downloads\download__15022_i1613125325_il540816.exe.rar

The file download__15022_i1613125325_il540816.exe.rar has been seen being distributed by the following URL.

Remove download__15022_i1613125325_il540816.exe.rar - Powered by Reason Core Security