skymonkam__2155_il341772.exe

Installer

Shetef Solutions & Consulting (1998) Ltd.

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application skymonkam__2155_il341772.exe by Shetef Solutions & Consulting (1998) has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the Amonetize Downloader installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from file.xmusic.me and multiple other hosts. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
Amonétizé Ltd  (signed by Shetef Solutions & Consulting (1998) Ltd.)

Product:
Installer

Version:
1.1.5.26

MD5:
483c854e9c91c575beb5b6fdc907e471

SHA-1:
1f7623c8c08c43cee17ff60bd562f9ab334dc2e6

SHA-256:
06e63cd5f211d9345263a38996756f25948960a75dbe62136825e0d97a32c2ae

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 4:30:50 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen2
7.11.110.34

avast!
Win32:Dropper-gen [Drp]
2014.9-140322

Bkav FE
W32.Clod2fe.Trojan
1.3.0.4261

Dr.Web
Adware.Downware.1575
9.0.1.081

ESET NOD32
Win32/Amonetize (variant)
8.8984

G Data
Win32.Trojan.Agent.5GNNCG
14.3.22

Malwarebytes
PUP.Optional.Amonetize
v2014.03.22.10

McAfee
Artemis!483C854E9C91
5600.7183

Reason Heuristics
PUP.Installer.ShetefSolutionsConsulting1998.Y
14.8.8.3

Trend Micro House Call
TROJ_GEN.F47V1017
7.2.81

VIPRE Antivirus
Conduit
22856

File size:
198.6 KB (203,392 bytes)

Product version:
2.1.12

Copyright:
(c) Amonétizé Ltd, 2012,2013. All rights reserved.

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Amonetize Downloader

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\skymonkam__2155_il341772.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/23/2013 3:00:00 AM

Valid to:
7/24/2014 2:59:59 AM

Subject:
CN=Shetef Solutions & Consulting (1998) Ltd., O=Shetef Solutions & Consulting (1998) Ltd., L=Rannana, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7C23DBB97FAFBB9D28D413F836202024

File PE Metadata
Compilation timestamp:
10/17/2013 8:12:35 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:ataMQya+XhanfoGxB9DLyvhZLWd8zehNivTRYuQKoalEsBzFv:WaMrUfoGHR0DDzeTiLRDlthv

Entry address:
0x69F90

Entry point:
60, BE, 00, E0, 43, 00, 8D, BE, 00, 30, FC, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8258

Packer / compiler:
UPX 2.90LZMA]

Code size:
180 KB (184,320 bytes)

The file skymonkam__2155_il341772.exe has been seen being distributed by the following 2 URLs.

http://file.xmusic.me/mp3/98270317/58375396/2547563162/.../Majli_Sajrus_-_Girls_Just_Wanna_Have_Fun_Breakout_(xMusic.me).mp3

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove skymonkam__2155_il341772.exe - Powered by Reason Core Security