Shetef Solutions & Consulting (1998) Ltd.

Publisher Information

Shetef Solutions & Consulting (1998) Ltd. is a software developer located in Rannana, Israel*. The company is a primary distributor of unwanted software. Shetef uses the Amonetize is a pay-per-insall monetization and distribution platform to distribute adware installers as well as other potentially unwanted software, mostly wrapping legitimate programs in adware bundles. Thre are 4 additional code signing certificates issued to this publisher.
Authority:
Thawte, Inc.

Valid from:
7/23/2013 2:00:00 AM

Valid to:
7/24/2014 1:59:59 AM

Subject:
CN=Shetef Solutions & Consulting (1998) Ltd., O=Shetef Solutions & Consulting (1998) Ltd., L=Rannana, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7c23dbb97fafbb9d28d413f836202024

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Amonetize.ShetefSo.Bundler (M), PUP.Amonetize (M)
100.00%

1 / 68      (Adware)
nethfdrv.sys (nethfdrv)  (0898c67217e9ac38e71e9e64ca34ac24)

1 / 68      (Adware)
nethfdrv.sys (nethfdrv)  (a1c77977b37c91d2a649fe840e9b9d55)

1 / 68      (Adware)
nethfdrv.sys (nethfdrv)  (f41b318c8bd52ca10ff41868e051824e)

1 / 68      (Adware)
nethfdrv.sys (nethfdrv)  (46ec660c1cac2892b02ca9246cdce571)

1 / 68      (Adware)
flashplayer__4369_i418823331_il280.exe (Install)  (5e8ef02d4e15460c33b7fae0df4ca79f)

1 / 68      (Adware)
setup__4298_il67.exe (Install)  (2be3b29d8cba249c79b7b04a80988546)

1 / 68      (Adware)
utorrent__4280_il3118.exe (Installer by Amônétízé)  (f6b1242c3a66565e3a2bd33f391ebd41)

1 / 68      (Adware)
emule050a.exe__2394_il99.exe (Installer by Amonétizé)  (8d0fc7188a954b03f32cf9fdb7c3da1b)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
flashplayer__3797_i403056945_il6734366.exe (Installer)  (1dedd3e7a9d27bfb94bfc4c492c27e12)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
nethfdrv.sys (nethfdrv)  (b760966facd61dda4eb2675e0391c09b)

1 / 68      (Adware)
onhax downloader__4006_il40.exe (Installer)  (7a301fa9cb0f8acf1425bdb4c229c9b7)

1 / 68      (Adware)
nethfdrv.sys (nethfdrv)  (e80ee1a578aa3bd261bd6c8500d40506)

1 / 68      (Adware)
anime downloader__3834_il4048460.exe (Installer)  (05a9ab037c8e03e0c3e6751603bebceb)

1 / 68      (Adware)
ow+vc0fq.exe (Installer by Amonétizé)  (55dd47e3ecac19e4e1ce397e83a3c7dd)

1 / 68      (Adware)
jgmtq9ad.exe (Installer by Amonetizé)  (df4b0cff3a12387b6cc1c656c37ba10e)

1 / 68      (Adware)
ow6sw2je.exe (Installer by Amonétizé)  (3490970a67665ca7ddaec9e30904d8e4)

1 / 68      (Adware)

1 / 68      (Adware)
setup__3061_il16232.exe (Installer by Amônétízé)  (8ef7d23aa91615ac9018c50270d0c393)

1 / 68      (Adware)
tvappsetup__2327_i412270637_il119.exe (Install)  (01d52c4f45b45131194e4e7365b723f9)

1 / 68      (Adware)
nethfdrv.sys (nethfdrv)  (dffead8185352e98230e7e70da3bf9a0)

1 / 68      (Adware)
tvappsetup__2327_i400789816_il119.exe (Installer)  (2373db18a78c32ff92c11636096f0ae2)

1 / 68      (Adware)

 
Latest 30 of 288 files

Downloads URLs for files signed by Shetef Solutions & Consulting (1998) Ltd..

1 / 68      (Adware)
q=http://tinyurl.com/p3s5g74  (megapolis hack__4012_i101516970_il4306781.exe)

1 / 68      (Adware)

The following websites host and distribute files published by Shetef Solutions & Consulting (1998) Ltd..

The certificates below are also signed by Shetef Solutions & Consulting (1998) Ltd..

4B1B72BCEFC0E8  (Oct 13, 2014 to Oct 13, 2015)

009E472EA7B4ADB461EB35F9F783DA3438  (Sep 26, 2014 to Sep 27, 2015)

4F0762A0FB4E2EA75260E9E77B74473E  (Jul 19, 2014 to Aug 19, 2015)

40812DA0F7CB2ECD4955FD76E0A6C493  (Feb 21, 2012 to Feb 21, 2013)

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to Shetef Solutions & Consulting (1998) Ltd. by Thawte, Inc. on July 23, 2013 with the serial number '7c23dbb97fafbb9d28d413f836202024'.