microsoft.project.professional.2010.with.sp1 zwtiso__3515_i979994463_il1609123.exe

Install Path Ltd

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application microsoft.project.professional.2010.with.sp1 zwtiso__3515_i979994463_il1609123.exe by Install Path has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the Amonetize Downloader installer. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Install Path Ltd  (signed and verified)

Version:
1.1.5.90

MD5:
1c6767a15581248a05a11b74631d71b3

SHA-1:
431c87f7bb9d2c86f12c26c1b8f491d75dcc17e1

SHA-256:
ea0de6f4753672969b8dd2c23a217ea8d93d9bf589e463ba6c62363cdea3bfdf

Scanner detections:
15 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/24/2024 4:12:45 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Amonetiz
2014.07.08

avast!
Win32:Amonetize-CI [PUP]
2014.9-151011

AVG
Generic
2016.0.2960

Baidu Antivirus
Adware.Win32.Amonetize
4.0.3.151011

Dr.Web
Adware.Downware.5488
9.0.1.0284

ESET NOD32
Win32/Amonetize.BF.gen (variant)
9.10062

Fortinet FortiGate
Riskware/Amonetize
10/11/2015

G Data
Win32.Application.Amonetize
15.10.24

IKARUS anti.virus
PUA.Amonetize
t3scan.1.6.1.0

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
14.0.0.1293

McAfee
Artemis!1C6767A15581
5600.6616

Reason Heuristics
PUP.Amonetize.InstallPath.Installer (M)
15.10.11.8

Sophos
Generic PUA ED
4.98

Trend Micro House Call
Suspicious_GEN.F47V0701
7.2.284

VIPRE Antivirus
Trojan.Win32.Generic
31082

File size:
325.4 KB (333,240 bytes)

Product version:
1.1.5.90

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Amonetize Downloader

Language:
English (United States)

Common path:
C:\users\{user}\downloads\microsoft.project.professional.2010.with.sp1 zwtiso__3515_i979994463_il1609123.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/30/2014 2:00:00 AM

Valid to:
4/30/2016 1:59:59 AM

Subject:
CN=Install Path Ltd, OU=Install Path Ltd, O=Install Path Ltd, STREET=5 Jabotinsky, L=Ramat Gan, S=(select one), PostalCode=5252006, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
11218EE2EBDA2A9FF91D21033208850D

File PE Metadata
Compilation timestamp:
6/24/2014 9:20:57 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:ZLaHr6lGYxpTBLkrNPX3joWnNMfKNI63GGYMsmJlyqn5QGwG:JamsYxpTGMUNI63GsOG

Entry address:
0xE2F7

Entry point:
E8, BA, 46, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 14, FD, 41, 00, 00, 75, 18, E8, B4, 3D, 00, 00, 6A, 1E, E8, FE, 3B, 00, 00, 68, FF, 00, 00, 00, E8, 97, F6, FF, FF, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40...
 
[+]

Code size:
82 KB (83,968 bytes)

The file microsoft.project.professional.2010.with.sp1 zwtiso__3515_i979994463_il1609123.exe has been seen being distributed by the following URL.