private_the_matador_3.exe

Tanja Matkovic

The application private_the_matador_3.exe by Tanja Matkovic has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The setup installer will bundle multiple adware offers during download and setup (based on the user's geographical location) including toolbars, extensions and coupon utilities. The file has been seen being downloaded from www.ft-download.com and multiple other hosts.
Publisher:
Tanja Matkovic  (signed and verified)

MD5:
adbcd8b3f655293bce1f74ccad17bb88

SHA-1:
9922abd9cca6e3f9800d23c4018c88b83a79401c

SHA-256:
eba0152261223834f79e7ac137ef1adfff12be48c368ed5c1ca54348e3073b06

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Bundles a number of adware programs in the installer.

Analysis date:
12/27/2024 11:23:24 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Malwarebytes
PUP.Optional.OneClickDownloader.A
v2014.01.11.09

McAfee
Artemis!ADBCD8B3F655
5600.7253

Reason Heuristics
PUP.TanjaMatkovic.V
14.3.29.10

VIPRE Antivirus
CoolMirage Ltd
24428

File size:
309.6 KB (317,040 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/30/2013 5:00:00 PM

Valid to:
5/1/2014 4:59:59 PM

Subject:
CN=Tanja Matkovic, OU=Individual Developer, O=No Organization Affiliation, L=Subotica, S=Subotica, C=RS

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6A3131F81D52E40A00F4396C56D649C5

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:Esk7M4vm0WNuzv+GipqMpOuiJe5/PCe1gwukxn3mbod7gphm+LUdv3Yp1zm2Az:wMdIvYqMEuv/PCeyG3WG7KhIip1C24

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.8397

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file private_the_matador_3.exe has been seen being distributed by the following 6 URLs.

Remove private_the_matador_3.exe - Powered by Reason Core Security