skijumpmania2generator__7934_il161424.exe

The application skijumpmania2generator__7934_il161424.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a setup program which is used to install the application. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from vfasterdownload.com.
MD5:
ac6943105e504e4114cd4bd4224b33d4

SHA-1:
a9c7a9655470e3770297c19f03ac580dd3102602

SHA-256:
428d4891f34af7a442a49e87031a336f429b96ac66f35400d30c1f9300e4bd69

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 6:59:36 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160118-1

ESET NOD32
Win32/Amonetize.OS potentially unwanted application
7.0.302.0

VIPRE Antivirus
Threat.4785227
46838

File size:
1.1 MB (1,180,875 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\skijumpmania2generator__7934_il161424.exe

File PE Metadata
Compilation timestamp:
1/31/2016 6:15:13 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:QlGsyI27CckvGXMTtZ+MaC0gQX2KWR7JM8l0WfI:QkN7iWMTtZ+M4gKO0p

Entry address:
0x6B56

Entry point:
E8, C8, 36, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 50, 31, C0, 89, D8, EB, 03, EB, 00, B8, 90, 90, EB, 03, B8, 83, F8, 58, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, A8, 27, 41, 00, FF, 15, 24, D0, 40, 00, 85, C0, 75, 18, 56, E8, B4, 24, 00, 00, 8B, F0, FF, 15, 20, D0, 40, 00, 50, E8, 52, 24, 00, 00, 59, 89, 06, 5E, 5D, C3, 8B, FF, 55, 8B, EC, 50, 31, C0, 89, D8, EB, 03, EB, 00, B8, 90, 90, EB, 03, B8, 83, F8, 58, 8B, C1, 8B, 4D, 08, C7, 00, 84, E2, 40, 00, 8B, 09, 89, 48, 04, C6, 40, 08...
 
[+]

Code size:
46 KB (47,104 bytes)

The file skijumpmania2generator__7934_il161424.exe has been seen being distributed by the following URL.

Remove skijumpmania2generator__7934_il161424.exe - Powered by Reason Core Security