setup__6666_i1536460061_il15265.exe.zip

The file setup__6666_i1536460061_il15265.exe.zip has been detected as a potentially unwanted program by 22 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from getfastddl.com.
MD5:
c49f64b1a9ecd69336a4af5af7c8e078

SHA-1:
fe3f13842401535e7e71dc99bd2e31815fc8affa

SHA-256:
ac383d29fa77def715b5ff5c030689d2bdbacf50ef13177ca4cde578b864a6d4

Scanner detections:
22 / 68

Status:
Potentially unwanted

Analysis date:
4/9/2025 8:24:40 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Amonetize.BA
5718107

Agnitum Outpost
PUA.Amonetize
7.1.1

Avira AntiVirus
ADWARE/Amonetize.637456.2
8.3.1.6

Arcabit
Application.Bundler.Amonetize.BA
1.0.0.425

avast!
Win32:PUP-gen [PUP]
2014.9-150621

AVG
BundleApp
2016.0.3071

Bitdefender
Application.Bundler.Amonetize.BA
1.0.20.860

Dr.Web
infected with Trojan.Amonetize.3647
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.Amonetize.BA
10.0.0.5366

ESET NOD32
Win32/Amonetize.FC potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Amonetize
6/21/2015

G Data
Application.Bundler.Amonetize.BA
15.6.25

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
15.0.0.543

Malwarebytes
PUP.Optional.Amonetize
v2015.06.21.02

McAfee
Program.Artemis!FF16922ED4A0
17.6.569.0

MicroWorld eScan
Application.Bundler.Amonetize.BA
16.0.0.516

NANO AntiVirus
Riskware.Win32.Amonetize.dsucco
0.30.24.2086

Norman
Application.Bundler.Amonetize.BA
02.06.2015 14:23:46

Panda Antivirus
Trj/Genetic.gen
15.06.21.02

Trend Micro House Call
Suspici.DDC462BB
7.2.172

VIPRE Antivirus
Trojan.Win32.Generic
41330

Zillya! Antivirus
Adware.Amonetize.Win32.4105
2.0.0.2240

File size:
533.3 KB (546,100 bytes)

Common path:
C:\users\{user}\downloads\setup__6666_i1536460061_il15265.exe.zip

The file setup__6666_i1536460061_il15265.exe.zip has been seen being distributed by the following URL.

Remove setup__6666_i1536460061_il15265.exe.zip - Powered by Reason Core Security