karaoke midi.exe

New IT Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application karaoke midi.exe by New IT Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from dc105.4shared.com.
Publisher:
New IT Limited  (signed and verified)

MD5:
9d69b4c8ee99adfc4e5bf5de921b63de

SHA-1:
2bf9ca5361f0cecbbd53b4b0f101dc12c60e7363

SHA-256:
1f919dfab2a797ca1ea4f1f018816e6094b4b35a79e0e57571a5fae9b2d25402

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/28/2024 12:28:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.New IT Limited.NewIT (M)
16.5.1.19

File size:
863.4 KB (884,080 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\karaoke midi.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
11/17/2012 12:16:05 AM

Valid to:
11/16/2013 10:30:34 PM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B2A165690BBAA

File PE Metadata
Compilation timestamp:
1/29/2013 9:13:39 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:orMU5GVoUPFAl+X5nmxvsGGXTzRVZq67f1:orhTkF2+pFGQsk

Entry address:
0x903D

Entry point:
E8, 8C, 43, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3...
 
[+]

Entropy:
6.3991

Code size:
85.5 KB (87,552 bytes)

The file karaoke midi.exe has been seen being distributed by the following URL.

Remove karaoke midi.exe - Powered by Reason Core Security