istrhr.dll

Pitaya Tech Ltd

The module istrhr.dll by Pitaya Tech has been detected as adware by 9 anti-malware scanners.
Publisher:
Pitaya Tech Ltd  (signed and verified)

MD5:
cfe4afdaee7c7646dea9dcb3bb6154ae

SHA-1:
35c506208f8f5001d93fb45d4386b7eedc239f19

SHA-256:
52ac12317014eadfe0f897af8b95c71956040a9076421e245a5271c5ee1bc034

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
11/23/2024 11:00:06 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Shopperz.A
657

Bitdefender
Adware.Shopperz.A
1.0.20.540

Dr.Web
Adware.Shopper.821
9.0.1.05190

Emsisoft Anti-Malware
Adware.Shopperz
8.15.04.18.04

F-Secure
Adware.Shopperz.A
11.2015-18-04_7

G Data
Adware.Shopperz
15.4.25

MicroWorld eScan
Adware.Shopperz.A
16.0.0.324

nProtect
Adware.Shopperz.A
15.03.27.01

Reason Heuristics
PUP.PitayaTech.G
14.12.11.23

File size:
864.8 KB (885,560 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\shop for rewards\istrhr.dll

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/21/2014 7:00:00 PM

Valid to:
9/22/2015 6:59:59 PM

Subject:
CN=Pitaya Tech Ltd, O=Pitaya Tech Ltd, STREET=Rakefet 19, L=Hod Hasharon, S=Sharon, PostalCode=4510034, C=IL

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6FAC939FE352559AD7790E9C81C9A639

File PE Metadata
Compilation timestamp:
11/2/2014 7:56:44 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:rO8fHBKJGSis4m2XzylPn0nSh0KvqmnRDrlQI84gA2lO7wPSdwmBphRz5:rphKE+4m2X2anSaKvq0Bxo4gjO75z5

Entry address:
0x94012

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, F8, F9, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 10, 2E, 0C, 10, E8, AF, 4E, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, B8, 83, 0C, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 70, 25, 0B, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.5290

Developed / compiled with:
Microsoft Visual C++

Code size:
699 KB (715,776 bytes)

Remove istrhr.dll - Powered by Reason Core Security