rigs of rods school bus downloader__3687_i1781335464_il1943774.exe.gz

The file rigs of rods school bus downloader__3687_i1781335464_il1943774.exe.gz has been detected as a potentially unwanted program by 17 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from www.uzwmv24amstgybpqngxxf.info and multiple other hosts.
MD5:
6386cf2a89d34402fee1fa2e8b870d38

SHA-1:
6556930375c223c72862eada1778351488226653

SHA-256:
b7d1e8b2874646f831ef6ab6bc872aa1249500886949313e3b0a527f75ce74d8

Scanner detections:
17 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 12:31:30 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Jaik.9671
5727219

Avira AntiVirus
ADWARE/Amonetize.Gen
8.3.2.4

Arcabit
Trojan.Adware.Jaik.D25C7
1.0.0.629

AVG
BundleApp
2016.0.2894

Bitdefender
Gen:Variant.Adware.Jaik.9671
1.0.20.1745

Dr.Web
infected with Trojan.Amonetize.11670
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Jaik.9671
10.0.0.5366

ESET NOD32
Win32/Amonetize.MZ potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Amonetize
12/15/2015

F-Secure
Gen:Variant.Adware.Jaik
11.2015-15-12_3

G Data
Gen:Variant.Adware.Jaik.9671
15.12.25

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
15.0.0.562

McAfee
Program.Artemis!B75BA58FB8D1
18.0.204.0

MicroWorld eScan
Gen:Variant.Adware.Jaik.9671
16.0.0.1047

NANO AntiVirus
Riskware.Win32.Amonetize.dzbkzd
1.0.10.5081

Panda Antivirus
Generic Suspicious
15.12.15.04

Sophos
Generic PUA AF (PUA)
4.98

File size:
744.4 KB (762,236 bytes)

Common path:
C:\users\{user}\downloads\rigs of rods school bus downloader__3687_i1781335464_il1943774.exe.gz

The file rigs of rods school bus downloader__3687_i1781335464_il1943774.exe.gz has been seen being distributed by the following 18 URLs.

http://www.uzwmv24amstgybpqngxxf.info/randownload.php?A512MgovjBN1sMA2NWQUNEcHcTUlMgFwYSV3F3DQYUPRUKEAM6fGFZV2Y0Jjs5aXUed0AoAkQ1LmkKUEgZZiwKDw0nLx51XToJAxkLJiRHF1UoEwYSMTYpVF9ZNAgaBgslJGgMWjkTH1NZA2QHdxd/.../SQwZB2dzc11dKghBBgQlZ0YAD3xRWBRbIHkMBlQpUllOXHR5AVIBdQZXRwhwcQ0AUSwCDRRbd3JUVQBrE15LW3Z1DAgEf1RaTg==

http://www.mark7hill.info/?ci=3422&version=1.1.5.26&prefix=Theme Park

http://www.mark10hill.info/?vn=1.1.5.26&campid=3687&prefix=Puzzle Dxf Collection Download Downloader&getid[thankyoupage]=http://.../?success&getid[interrupted]=http://.../?cancel&ti1=1809421806&getid[appsetupurl]=http://fastmediadownloads.com/download/Prompt-Downloader-1809421806.exe&appname=Puzzle Dxf Collection Download Downloader&getid[cmdline]=&getid[appimageurl]=http://.../logo.png

http://abc.mobile-10.com/mobi?k=89941ffe0d6b8be725633652c03c22e7&q=ClashBot 7.3 Works with Clash of Clans Update Bug Fixes

http://www.mark10hill.info/?vn=1.1.5.26&campid=3687&prefix=Mr Magorium S Wonder Emporium Downloader&getid[thankyoupage]=http://.../?success&getid[interrupted]=http://.../?cancel&ti1=1128483300&getid[appsetupurl]=http://fastmediadownloads.com/download/Prompt-Downloader-1128483300.exe&appname=Mr Magorium S Wonder Emporium 2007 Eng Divx Downloader&getid[cmdline]=&getid[appimageurl]=http://.../logo.png