ms.ar.cookies.1.4.2.rar__4607_i181716932_il264.exe

Installer

The application ms.ar.cookies.1.4.2.rar__4607_i181716932_il264.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from getmdownloader.com and multiple other hosts. While running, it connects to the Internet address www.ibbalance.com on port 443.
Product:
Installer

Version:
1.1.6.20

MD5:
c7ad3fb171278bc346278be020e69209

SHA-1:
3a854fc632d6e807edfc143c9418a1cbbf3bd7c3

SHA-256:
fdf920685b8474c4f5afc1b7e054127c689d480c8408714d3d7afb719edc2a2f

Scanner detections:
9 / 68

Status:
Potentially unwanted

Analysis date:
12/24/2024 11:24:12 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Rootkit-gen [Rtk]
2014.9-131225

Dr.Web
Adware.Downware.1729
9.0.1.0359

ESET NOD32
Win32/Amonetize (variant)
7.9179

G Data
Win32.Trojan.Agent.K58KBG
13.12.22

K7 AntiVirus
Trojan
13.174.10530

Malwarebytes
PUP.Optional.Monetizer
v2013.12.25.11

McAfee
RDN/Generic.hra!bv
5600.7270

Trend Micro House Call
TROJ_GEN.R0CBH06LG13
7.2.359

VIPRE Antivirus
Trojan.Win32.Generic
24434

File size:
325 KB (332,800 bytes)

Product version:
2.1.12

Copyright:
(c) 2012,2013. All rights reserved.

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\ms.ar.cookies.1.4.2.rar__4607_i181716932_il264.exe

File PE Metadata
Compilation timestamp:
12/5/2013 6:31:09 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:mwnynivy4YAfxPXa61WPhDR4Bw3BSeC+NEHwUtWNHTJIHU1r33C4+p:JnUiqYf31WPhDRgw3wcEHwXNzJIHTp

Entry address:
0x27146

Entry point:
E8, 81, 96, 00, 00, E9, 89, FE, FF, FF, 57, 8B, C6, 83, E0, 0F, 85, C0, 0F, 85, C1, 00, 00, 00, 8B, D1, 83, E1, 7F, C1, EA, 07, 74, 65, EB, 06, 8D, 9B, 00, 00, 00, 00, 66, 0F, 6F, 06, 66, 0F, 6F, 4E, 10, 66, 0F, 6F, 56, 20, 66, 0F, 6F, 5E, 30, 66, 0F, 7F, 07, 66, 0F, 7F, 4F, 10, 66, 0F, 7F, 57, 20, 66, 0F, 7F, 5F, 30, 66, 0F, 6F, 66, 40, 66, 0F, 6F, 6E, 50, 66, 0F, 6F, 76, 60, 66, 0F, 6F, 7E, 70, 66, 0F, 7F, 67, 40, 66, 0F, 7F, 6F, 50, 66, 0F, 7F, 77, 60, 66, 0F, 7F, 7F, 70, 8D, B6, 80, 00, 00, 00, 8D, BF...
 
[+]

Entropy:
6.4213

Code size:
230.5 KB (236,032 bytes)

The file ms.ar.cookies.1.4.2.rar__4607_i181716932_il264.exe has been seen being distributed by the following 7 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):