setup__7123_il942373.exe

Install Path Ltd

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup__7123_il942373.exe by Install Path has been detected as adware by 25 anti-malware scanners. The program is a setup application that uses the Amonetize Downloader installer. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Install Path Ltd  (signed and verified)

Version:
1.1.5.90

MD5:
d96b46f154978ead8adf136b5e78eddf

SHA-1:
01b0585e191d922d743d43e410aa930a10a2e43a

Scanner detections:
25 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/23/2024 12:44:08 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Jatif.103
719

Agnitum Outpost
PUA.Amonetize
7.1.1

AhnLab V3 Security
PUP/Win32.Amonetiz
2015.02.15

Avira AntiVirus
ADWARE/Adware.Gen4
7.11.210.58

AVG
InstallPath.7F5
2016.0.3197

Baidu Antivirus
Adware.Win32.Amonetize
4.0.3.15215

Bitdefender
Gen:Variant.Application.Jatif.103
1.0.20.230

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.Amonetize.DE
21079

Dr.Web
Trojan.Amonetize.441
9.0.1.046

ESET NOD32
Win32/Amonetize.DE potentially unwanted (variant)
9.11177

Fortinet FortiGate
Adware/Amonetize
2/15/2015

F-Secure
Gen:Variant.Application.Jatif
11.2015-15-02_1

G Data
Gen:Variant.Application.Jatif.103
15.2.25

K7 AntiVirus
Unwanted-Program
13.194.14967

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
14.0.0.2481

Malwarebytes
PUP.Optional.Amonetize
v2015.02.15.06

McAfee
GenericR-CXP!D96B46F15497
5600.6853

MicroWorld eScan
Gen:Variant.Application.Jatif.103
16.0.0.138

NANO AntiVirus
Trojan.Win32.Amonetize.dnjxrs
0.30.0.65070

Reason Heuristics
PUP.Installer.Amonetize
15.2.15.18

Sophos
Generic PUA AB
4.98

Trend Micro House Call
Suspicious_GEN.F47V0208
7.2.46

VIPRE Antivirus
Trojan.Win32.Generic
37562

Zillya! Antivirus
Adware.Amonetize.Win32.2183
2.0.0.2067

File size:
639.6 KB (654,952 bytes)

Product version:
1.1.5.90

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Amonetize Downloader

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\setup__7123_il942373.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/19/2015 10:00:00 AM

Valid to:
1/20/2016 9:59:59 AM

Subject:
CN=Install Path Ltd, OU=Install Path Ltd, O=Install Path Ltd, POBox=5252006, STREET=5 Jabotinsky, L=Ramat Gan, S=Israel, PostalCode=5252006, C=IL

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2E1A17FA8AA2A44E9135D585D48E6C41

File PE Metadata
Compilation timestamp:
1/29/2015 1:40:05 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:WRvec5T/QT8zse3S0x+6NVvnu6jHfpJ0XhCe75WR+NDehZk:Wpec5ToT8zs0S0l4wpJKT7IR+Ehm

Entry address:
0xDEB8

Entry point:
E8, C1, 4A, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 3D, EC, 1E, 38, 00, 00, 75, 18, E8, 9F, 34, 00, 00, 6A, 1E, E8, E9, 32, 00, 00, 68, FF, 00, 00, 00, E8, F0, F8, FF, FF, 59, 59, 8B, 45, 08, 85, C0, 75, 01, 40, 50, 6A, 00, FF, 35, EC, 1E, 38, 00, FF, 15, 9C, 70, 37, 00, 5D, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, EC, 1E, 38, 00, 00, 75, 18, E8, 55, 34, 00, 00, 6A, 1E, E8, 9F, 32, 00, 00, 68, FF, 00, 00, 00, E8, A6, F8, FF, FF, 59, 59, 85, DB, 74, 04, 8B, C3...
 
[+]

Code size:
148.5 KB (152,064 bytes)

The file setup__7123_il942373.exe has been seen being distributed by the following URL.

Remove setup__7123_il942373.exe - Powered by Reason Core Security