installer19__7934_il20618.exe

The application installer19__7934_il20618.exe has been detected as a potentially unwanted program by 13 anti-malware scanners. This is a setup program which is used to install the application. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from goo.gl and multiple other hosts.
Version:
1.1.5.90

MD5:
68bd90014903e9e9e4fa64e6f4350dbb

SHA-1:
7192002bff62ec2631305ffb7f7952c2c7918a3d

SHA-256:
d123bc386cf87b8bcf7265859f75e2929df3c0e96aad4c237555bb8ffe4a628c

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 8:29:58 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Barys.82
704

AhnLab V3 Security
PUP/Win32.Amonetiz
2015.02.26

Avira AntiVirus
ADWARE/Adware.Gen2
7.11.212.142

Bitdefender
Gen:Variant.Barys.82
1.0.20.310

Bkav FE
HW32.Packed
1.3.0.6379

Emsisoft Anti-Malware
Gen:Variant.Barys.82
8.15.03.03.01

G Data
Gen:Variant.Barys.82
15.3.25

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
14.0.0.2405

Malwarebytes
PUP.Optional.Amonetize
v2015.03.03.01

McAfee
Artemis!68BD90014903
5600.6838

MicroWorld eScan
Gen:Variant.Barys.82
16.0.0.186

Qihoo 360 Security
HEUR/QVM16.0.Malware.Gen
1.0.0.1015

Quick Heal
(Suspicious) - DNAScan
3.15.14.00

File size:
715.5 KB (732,672 bytes)

Product version:
1.1.5.90

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\installer19__7934_il20618.exe

File PE Metadata
Compilation timestamp:
2/25/2015 2:01:10 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:K8J1blKfyYTuE//vL1l4bwto92fesVo3bdBoDno/RHEQMNf1C7V7+m8CvKp:KwpK6D2vhl4blmesV2bfoDoJtMNNaIpb

Entry address:
0xC6D27

Entry point:
E8, 1C, 25, 00, 00, E9, 3A, F2, 13, CA, 10, E5, B4, 0C, DD, 8F, CD, 22, 4E, 77, C2, 3F, EE, 76, 11, C7, 09, 65, FA, F3, 1A, 4B, A8, 8F, B5, 0E, 12, 02, B9, 40, 9D, 9B, AA, 38, 18, AD, 79, 6A, 11, D8, D3, C0, 15, 55, 24, 38, E2, 59, 52, C9, 10, A7, 47, A6, 72, 93, CD, 89, DB, 9F, 7E, A4, 55, 8F, E1, A5, 4D, AC, 65, BF, 63, 82, 47, FD, 5D, 70, E4, 64, C2, 0A, C5, 9F, 4B, E0, 55, 8D, 6C, 9B, BB, 09, 69, A8, 32, 9C, 29, B5, 2E, 8D, 2E, 77, AF, 4E, 9B, AC, B9, 93, 63, C8, E0, 69, 02, B4, 5D, B1, 96, 6F, 62, 7C...
 
[+]

Entropy:
7.8630  (probably packed)

Code size:
353 KB (361,472 bytes)

The file installer19__7934_il20618.exe has been seen being distributed by the following 2 URLs.

Remove installer19__7934_il20618.exe - Powered by Reason Core Security