minecraft_awesome_redstone_map_downloader.exe

SimpleFiles Installer

New Monte Inc

The application minecraft_awesome_redstone_map_downloader.exe by New Monte Inc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the SimpleFiles installer. The installer is marketed through download protals and search ads as Minecraft but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
New Monte Inc  (signed and verified)

Product:
SimpleFiles Installer

Version:
1, 0, 511, 1

MD5:
154d7d2344192cb2d31d6dedce36caa1

SHA-1:
ae6677eb511c2a7667ad5e3561f72b24ed8f6502

SHA-256:
0f974860f2b2de42e399b655499bf3b3203aaf71bd5534ba72b3a363fa3fd64a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
11/30/2024 10:03:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Blisbury (M)
17.3.16.6

File size:
3.9 MB (4,045,624 bytes)

Product version:
1.0.0.1

Copyright:
Copyright http://simple-files.com (C) 2014

Original file name:
SimpleFilesInstaller.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SimpleFiles

Language:
English

Common path:
C:\users\{user}\downloads\minecraft_awesome_redstone_map_downloader.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
12/1/2013 7:00:00 PM

Valid to:
12/6/2016 7:00:00 AM

Subject:
CN=New Monte Inc, O=New Monte Inc, L=Mahe, S=Seychelles, C=SC

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0EF12F8AD3F2DFB7CD5C8F46FEE59C5C

File PE Metadata
Compilation timestamp:
1/23/2015 5:58:06 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x7BE0BB

Entry point:
9C, E8, F3, CC, FF, FF, 0F, 99, C0, 98, 8D, 05, A3, 1C, BC, 00, E9, 29, CF, C7, FF, 9C, 9C, 89, 44, 24, 08, F6, D0, F6, D0, 9C, 9C, AC, 66, 39, C7, 2C, 51, F5, F5, 9C, C0, C0, 07, E9, 88, E5, C9, FF, F6, D0, 9C, C0, C0, 02, E9, FE, 64, C9, FF, 26, 25, 7C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 54, F4, 7B, 00, 00, 60, 45, 00, 2E, 25, 7C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 49, BB, 43, 00, 08, 60, 45, 00, 36, 25, 7C, 00, 00, 00, 00, 00, 00, 00, 00, 00, BC, 21, 7C, 00, 10, 60, 45, 00, 3E, 25, 7C, 00, 00, 00, 00...
 
[+]

Code size:
972 KB (995,328 bytes)

Windows Firewall Allowed Program
Name:
simplefiles