SilentInstaller_dotnet2.exe

am1303

The application SilentInstaller_dotnet2.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. This is a setup program which is used to install the application. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. The file has been seen being downloaded from d172h6aeftm6ez.cloudfront.net.
Product:
am1303

Version:
3.0.1.3

MD5:
aae7fabb2621ca55f1129cca938c45d5

SHA-1:
ce454b25bd5740b1bc59c5df6cf2f418a9c2e668

Scanner detections:
16 / 68

Status:
Potentially unwanted

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
11/25/2024 4:10:55 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Razy.18672
328

AhnLab V3 Security
PUP/Win32.OfferInstaller
2016.03.13

Avira AntiVirus
TR/Dropper.MSIL.Gen
8.3.3.2

Arcabit
Trojan.Razy.D48F0
1.0.0.657

avast!
Win32:Adware-gen [Adw]
2014.9-160313

Bitdefender
Gen:Variant.Razy.18672
1.0.20.365

Dr.Web
Trojan.Crossrider1.57003
9.0.1.073

Emsisoft Anti-Malware
Gen:Variant.Razy.18672
8.16.03.13.07

ESET NOD32
MSIL/Adware.Imali (variant)
10.13169

F-Secure
Gen:Variant.Razy.18672
11.2016-13-03_1

G Data
Gen:Variant.Razy.18672
16.3.25

IKARUS anti.virus
AdWare.MSIL.Imali
t3scan.2.0.9.0

MicroWorld eScan
Gen:Variant.Razy.18672
17.0.0.219

Panda Antivirus
Trj/GdSda.A
16.03.13.07

Qihoo 360 Security
QVM03.0.Malware.Gen
1.0.0.1120

Trend Micro House Call
HT_IMALI_FB250001.UVPM
7.2.73

File size:
313.5 KB (321,024 bytes)

Product version:
3.0.1.3

Copyright:
Copyright © 2016

Original file name:
SilentInstaller_dotnet2.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\silentinstaller_dotnet2.exe

File PE Metadata
Compilation timestamp:
3/13/2016 9:05:27 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:BQFZT8qbTR7SquD4L8vioH/X8i9DLnHWcefjVo8bS5Vktxz+L:CZwgVxGq86oH/MKvnolgs4

Entry address:
0x4F23E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
309 KB (316,416 bytes)

The file SilentInstaller_dotnet2.exe has been seen being distributed by the following URL.

Remove SilentInstaller_dotnet2.exe - Powered by Reason Core Security