steam codes.exe__15022_i1732540490_il699020.ace

The file steam codes.exe__15022_i1732540490_il699020.ace has been detected as a potentially unwanted program by 7 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from mediafiretrend.com.
MD5:
adcc3d2ed54738ccaf8109f090cf6ea9

SHA-1:
19ffee8be80054d303541c207513e347d66c6ed1

SHA-256:
709796676c0ef5bc911c4b63416898b72c1fcfc9fd956e5c573b15e1f43fe21f

Scanner detections:
7 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 5:42:32 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Amonetize.47
5708455

Dr.Web
infected with Trojan.Amonetize.10504
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Amonetize.47
10.0.0.5366

ESET NOD32
Win32/Amonetize.LF potentially unwanted application
7.0.302.0

Kaspersky
not-a-virus:Downloader.Win32.AdLoad
15.0.0.562

Norman
Gen:Variant.Application.Bundler.Amonetize.47
07.10.2015 03:16:12

Reason Heuristics
PUP.Amonetize (M)
16.1.6.22

File size:
657.3 KB (673,100 bytes)

Common path:
C:\users\{user}\downloads\steam codes.exe__15022_i1732540490_il699020.ace

The file steam codes.exe__15022_i1732540490_il699020.ace has been seen being distributed by the following URL.