satzo_password_hacking_software_2_4_free_full_version.exe

DOZ-DEKORUM LLC

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application satzo_password_hacking_software_2_4_free_full_version.exe by DOZ-DEKORUM has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Amonetize Downloader installer. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
CRJCZ  (signed by DOZ-DEKORUM LLC)

Product:
CRJCZ

Version:
4991.15625.818.7144

MD5:
1e5231aed856cced92dbd822a52cc234

SHA-1:
9e5a9589cd2f85e66b0b9c94fd42c619bda742bc

SHA-256:
4cb5dd327fd75c90a4b433af49168f5535d0e67c1f432e71681f07e9f7e38a01

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/30/2024 10:54:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize.DOZDEKOR.Bundler (M)
16.4.28.12

File size:
660.8 KB (676,680 bytes)

Product version:
4991.15625.818.7144

Copyright:
CRJCZ

Trademarks:
CRJCZ

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Amonetize Downloader (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\satzo_password_hacking_software_2_4_free_full_version.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
1/12/2015 5:30:00 AM

Valid to:
1/13/2016 5:29:59 AM

Subject:
CN=DOZ-DEKORUM LLC, O=DOZ-DEKORUM LLC, L=Kyiv, S=Kyiv, C=UA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
69D6CF0DB0DC468848F5B0AAC12F23DD

File PE Metadata
Compilation timestamp:
12/6/2009 4:22:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:OG6upRmHrGw+13Pqr2/t0MSeVFT7YyhVsV3E458axX/1Ffc8vy4hc:OfujmKwWyrNMVJUi3458y/1a86Z

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9491

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file satzo_password_hacking_software_2_4_free_full_version.exe has been seen being distributed by the following URL.