setup__6666_i1536460061_il15265.exe.zip
The file setup__6666_i1536460061_il15265.exe.zip has been detected as a potentially unwanted program by 22 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from getfastddl.com.
File name:
setup__6666_i1536460061_il15265.exe.zip
MD5:
c49f64b1a9ecd69336a4af5af7c8e078
SHA-1:
fe3f13842401535e7e71dc99bd2e31815fc8affa
SHA-256:
ac383d29fa77def715b5ff5c030689d2bdbacf50ef13177ca4cde578b864a6d4
Scanner detections:
22 / 68
Status:
Potentially unwanted
Analysis date:
4/9/2025 8:24:40 AM UTC (today)
Scan engine
Detection
Engine version
Lavasoft Ad-Aware
Application.Bundler.Amonetize.BA
5718107
Agnitum Outpost
PUA.Amonetize
7.1.1
Avira AntiVirus
ADWARE/Amonetize.637456.2
8.3.1.6
Arcabit
Application.Bundler.Amonetize.BA
1.0.0.425
avast!
Win32:PUP-gen [PUP]
2014.9-150621
Bitdefender
Application.Bundler.Amonetize.BA
1.0.20.860
Dr.Web
infected with Trojan.Amonetize.3647
9.0.1.05190
Emsisoft Anti-Malware
Application.Bundler.Amonetize.BA
10.0.0.5366
ESET NOD32
Win32/Amonetize.FC potentially unwanted application
7.0.302.0
Fortinet FortiGate
Adware/Amonetize
6/21/2015
G Data
Application.Bundler.Amonetize.BA
15.6.25
Kaspersky
not-a-virus:AdWare.Win32.Amonetize
15.0.0.543
Malwarebytes
PUP.Optional.Amonetize
v2015.06.21.02
McAfee
Program.Artemis!FF16922ED4A0
17.6.569.0
MicroWorld eScan
Application.Bundler.Amonetize.BA
16.0.0.516
NANO AntiVirus
Riskware.Win32.Amonetize.dsucco
0.30.24.2086
Norman
Application.Bundler.Amonetize.BA
02.06.2015 14:23:46
Panda Antivirus
Trj/Genetic.gen
15.06.21.02
Trend Micro House Call
Suspici.DDC462BB
7.2.172
VIPRE Antivirus
Trojan.Win32.Generic
41330
Zillya! Antivirus
Adware.Amonetize.Win32.4105
2.0.0.2240
File size:
533.3 KB (546,100 bytes)
Common path:
C:\users\{user}\downloads\setup__6666_i1536460061_il15265.exe.zip
The file setup__6666_i1536460061_il15265.exe.zip has been seen being distributed by the following URL.