five nights at freddy’s for pc.exe

volens eloquentia XLII-II

trepide

The application five nights at freddy’s for pc.exe, “fulgeo mansuetus cometes” has been detected as a potentially unwanted program by 9 anti-malware scanners. This is a setup program which is used to install the application. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from sunkfile.com.
Publisher:
trepide

Product:
volens eloquentia XLII-II

Description:
fulgeo mansuetus cometes

Version:
0.91.17.25

MD5:
96cc34f878dafbdcce5859437e28bfa8

SHA-1:
59bb7b83d0dd434086f02c015baf48ec16ac43d5

SHA-256:
3cb3960ce9e51534ddec63e86074e0cade5f05514b7b26d91a6ff3ef89a6a7a0

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
Uses the Solimba installer to bundle adware offers.

Analysis date:
11/24/2024 10:35:25 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
MSIL:Solimba-Z [PUP]
160518-2

AVG
Adware BundleApp_r.AV
2015.0.4591

Dr.Web
Adware.Downware.8808
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.Morstar.L
11.5.0.6191

ESET NOD32
MSIL/Solimba.AH potentially unwanted application
8.0.319.0

Kaspersky
not-a-virus:Downloader.Win32.Morstar
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.223.1749.0

Norman
Application.Bundler.Morstar.L
28.05.2016 15:32:18

VIPRE Antivirus
Threat.4150696
49574

File size:
523.2 KB (535,807 bytes)

Product version:
24.15.34.38

Copyright:
Copyright specto

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\five nights at freddy’s for pc.exe

File PE Metadata
Compilation timestamp:
10/14/2014 11:27:27 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:xTySyXMWfPTuNnB2WfFZ9dQ+rHhl4ZDdlxipv1snRotIS:xTySy9PTUnhfU2Hhl4DdlIcRotIS

Entry address:
0xDEDC

Entry point:
E8, AE, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, D8, 6F, 42, 00, E8, FE, 15, 00, 00, E8, 7F, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 41, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 0A, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.7024  (probably packed)

Code size:
113.5 KB (116,224 bytes)

The file five nights at freddy’s for pc.exe has been seen being distributed by the following URL.

Remove five nights at freddy’s for pc.exe - Powered by Reason Core Security