ff9a4ffe-097d-4a45-b50c-206787ad8fcd.exe

Downloader205

QUALITY SCORE SL

The application ff9a4ffe-097d-4a45-b50c-206787ad8fcd.exe by QUALITY SCORE SL has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
QUALITY SCORE SL  (signed and verified)

Product:
Downloader205

Version:
1.1.0.0

MD5:
4bdc35c599e811ce1b5925fad5cb6ddd

SHA-1:
3fc2c1c6a0807528bdb40e5e89fdf15b7172d188

SHA-256:
2d9447518a9f80531ecda8e1a4e7f710d142e91005c52822cfa1c83b048eea1c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/30/2024 8:00:59 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.17.10

File size:
604.8 KB (619,320 bytes)

Product version:
1.1.0.0

Copyright:
Copyright © 2013

Original file name:
Bundle.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\ff9a4ffe-097d-4a45-b50c-206787ad8fcd.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/2/2014 1:00:00 AM

Valid to:
1/3/2015 12:59:59 AM

Subject:
CN=QUALITY SCORE SL, O=QUALITY SCORE SL, STREET=CALLE SERRANO 213, L=MADRID, S=MADRID, PostalCode=28016, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4AB0F061E1C305B4B31A8ACE3AEA2E01

File PE Metadata
Compilation timestamp:
4/4/2014 11:09:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x8E5AE

Entry point:
FF, 25, BC, E5, 48, 00, 00, 00, 00, 00, 00, 00, 00, 00, 90, E5, 08, 00, 00, 00, 00, 00, 00, 00, 00, 00, 74, 1F, 3F, 53, 00, 00, 00, 00, 02, 00, 00, 00, 6E, 00, 00, 00, E0, E5, 08, 00, E0, C7, 08, 00, 52, 53, 44, 53, 02, 3A, 9F, 46, D4, 92, 32, 4C, 86, C8, D5, 90, 51, 5F, B2, CF, 01, 00, 00, 00, 43, 3A, 5C, 55, 73, 65, 72, 73, 5C, 69, 6B, 61, 72, 70, 75, 6B, 5C, 47, 6F, 6F, 67, 6C, 65, 20, 44, 72, 69, 76, 65, 5C, 50, 72, 6F, 79, 65, 63, 74, 6F, 73, 5C, 32, 30, 35, 2D, 69, 6E, 73, 74, 61, 6C, 6C, 65, 72, 5C...
 
[+]

Code size:
562 KB (575,488 bytes)

Remove ff9a4ffe-097d-4a45-b50c-206787ad8fcd.exe - Powered by Reason Core Security