photodexproshowproducer5setup-n1pytbvdz.exe

Somoto Ltd.

Somoto uses a monetization platform known as the 'Better Installer' to provide the ability of 3rd party developers to bundle various adware packages through an affiliate pay-per-install program. The application photodexproshowproducer5setup-n1pytbvdz.exe by Somoto has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the Somoto BetterInstaller installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from www.downloadab.com and multiple other hosts.
Publisher:
Somoto Ltd.  (signed and verified)

MD5:
aa7f6fe9339acfa8c21188d003ee6560

SHA-1:
e6ae9755085714f3073a0e35b5dde4fd3f20a114

SHA-256:
e13460e1bed268745bd4669c1f47fdf34c773e05307aa4cd57cd3e2dc473fbab

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Uses the Somoto 'BetterInstaller' to bundle additional (unwanted) software during install without adequate consent.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/23/2024 9:35:32 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Somoto.Gen2
7.11.142.108

avast!
Win32:Somoto-O [PUP]
2014.9-140410

AVG
Downloader
2015.0.3508

Baidu Antivirus
Adware.Win32.Somoto
4.0.3.14410

Clam AntiVirus
Trojan.Agent-267630
0.98/18355

Dr.Web
Trojan.MulDrop4.11744
9.0.1.0100

ESET NOD32
Win32/Somoto
8.9660

G Data
NSIS.Application.Somoto
14.4.24

K7 AntiVirus
Unwanted-Program
13.176.11721

Malwarebytes
PUP.Optional.Somoto.A
v2014.04.10.06

McAfee
Artemis!AA7F6FE9339A
5600.7164

Panda Antivirus
PUP/MultiToolbar.A
14.04.10.06

Qihoo 360 Security
Win32/Virus.Downloader.394
1.0.0.1015

Reason Heuristics
PUP.Installer.Somoto.h
14.8.7.17

Sophos
Somoto BetterInstaller
4.98

Trend Micro House Call
TROJ_GEN.F47V0406
7.2.100

VIPRE Antivirus
Trojan.Win32.Generic
28194

File size:
231.4 KB (236,960 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Somoto BetterInstaller

Common path:
C:\users\{user}\downloads\photodexproshowproducer5setup-n1pytbvdz.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/20/2011 2:00:00 AM

Valid to:
9/20/2014 1:59:59 AM

Subject:
CN=Somoto Ltd., O=Somoto Ltd., STREET=PO Box 58096, L=Tel Aviv, S=--, PostalCode=61580, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00841D099D16B738F34172FEEFE1D2574F

File PE Metadata
Compilation timestamp:
12/17/2010 10:14:15 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
6144:AJ380omGMY0Zq9O8eiRgQUYklM/hS23AOFvggAP9:AF80omG768PRgdY1IHIvgF

Entry address:
0x380C

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, 7C, 01, 00, 00, E8, 87, 4D, 00, 00, 83, EC, 0C, 68, 01, 80, 00, 00, E8, 2A, 4A, 00, 00, 6A, 00, E8, 9B, 4D, 00, 00, 6A, 08, A3, 28, F9, 42, 00, E8, B1, 28, 00, 00, 6A, 00, 68, 60, 01, 00, 00, A3, D8, F9, 42, 00, 8D, 85, 90, FE, FF, FF, 50, 6A, 00, 68, 4C, A2, 40, 00, E8, E0, 4C, 00, 00, 83, EC, 0C, 68, 4D, A2, 40, 00, 68, 08, FA, 42, 00, E8, EF, 2A, 00, 00, 83, C4, 18, E8, E6, 49, 00, 00, 52, 52, 50, 68, 00, 80, 43, 00, E8, DA, 2A, 00, 00, 57, 6A, 00, E8, 29, 49, 00, 00, 83...
 
[+]

Code size:
30 KB (30,720 bytes)

The file photodexproshowproducer5setup-n1pytbvdz.exe has been seen being distributed by the following 2 URLs.

http://www.downloadab.com/.../FLVPlayerSetup-N91WePcmz.exe

Remove photodexproshowproducer5setup-n1pytbvdz.exe - Powered by Reason Core Security