straight-talk-zte-merit-stock-rom_downloader.exe

SmileFiles Installer

Faglaro Enterprises Limited

The application straight-talk-zte-merit-stock-rom_downloader.exe by Faglaro Enterprises Limited has been detected as adware by 22 anti-malware scanners. The program is a setup application that uses the SimpleFiles installer. The file has been seen being downloaded from d.failsmail.com.
Publisher:
http://smile-files.com  (signed by Faglaro Enterprises Limited)

Product:
SmileFiles Installer

Version:
1, 0, 524, 1

MD5:
deed7efe078ec4250ac9e97585443867

SHA-1:
e40b40a73c78409e9a25b028a714715e9949f3f5

SHA-256:
9c415f469ac26b480b44060e66fa52100b7a9791a2ea97589f03dfd791036097

Scanner detections:
22 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/14/2024 9:10:41 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.79472
676

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/Downloader.Gen4
3.6.1.96

avast!
Win32:Downloader-TSH [PUP]
2014.9-150331

AVG
Faglaro Enterprises Limited
2016.0.3154

Bitdefender
Gen:Variant.Strictor.79472
1.0.20.450

Comodo Security
Virus.Win32.Virut.CE
21597

Dr.Web
Adware.Downware.10330
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Strictor.79472
8.15.03.31.05

ESET NOD32
Win32/ExpressDownloader.K potentially unwanted application
9.7.0.302.0

F-Secure
Gen:Variant.Strictor.79472
11.2015-31-03_3

G Data
Gen:Variant.Strictor.79472
15.3.25

IKARUS anti.virus
PUA.Expressdownloader
t3scan.1.8.9.0

K7 AntiVirus
Unwanted-Program
13.202.15432

Malwarebytes
PUP.Optional.SmileFiles.A
v2015.03.31.05

MicroWorld eScan
Gen:Variant.Strictor.79472
16.0.0.270

Panda Antivirus
Trj/Genetic.gen
15.03.31.05

Reason Heuristics
PUP.Installer.FaglaroEnterprises
15.3.31.5

Sophos
Smile Files Downloader
4.98

VIPRE Antivirus
Threat.4783941
38552

Zillya! Antivirus
Trojan.TDSS.Win32.43438
2.0.0.2122

File size:
3.2 MB (3,327,376 bytes)

Product version:
1.0.0.1

Copyright:
Copyright http://smile-files.com (C) 2014

Original file name:
SmileFiles.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SimpleFiles

Language:
English

Common path:
C:\users\{user}\downloads\straight-talk-zte-merit-stock-rom_downloader.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/12/2012 4:00:00 PM

Valid to:
12/13/2015 3:59:59 PM

Subject:
CN=Faglaro Enterprises Limited, O=Faglaro Enterprises Limited, STREET=Boumpoulinas 11, L=Nicosia, S=Nicosia, PostalCode=1060, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
37B080A790663B8AF63D05448AD0343B

File PE Metadata
Compilation timestamp:
3/10/2015 2:11:18 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
98304:/NIyKncBzTEJGDf83jyZTd9/hGfXmZfJkZqA1w0px:lIHnclOGD8UhG+DOqMw0px

Entry address:
0x1A71BB

Entry point:
50, E9, C4, 09, 00, 00, CD, BD, F3, 86, 45, CF, C4, 68, 75, BF, 2E, 20, E2, 76, D1, CF, 36, 22, BF, AD, 7B, 15, B5, 43, D8, FE, D4, 92, B4, 2B, A5, 08, FC, A1, 9B, 2E, 1A, EE, 76, 4C, E8, 93, 03, 5A, 5A, 9C, 62, B0, F2, 25, 94, 90, B2, BC, FE, EB, 58, BE, 04, 00, 62, B7, 53, 3A, C8, FE, 68, 04, 70, B9, 1F, 60, 78, 72, E9, 5D, A6, 36, EC, 2D, 42, 6C, 81, E9, 39, 09, 9E, 12, 78, 6D, F1, D3, 6D, 8D, 72, 0F, 15, 4B, C3, D1, 99, 7F, 61, F7, CD, B3, F2, 99, 49, A3, 9E, A3, 09, 40, B8, D1, 3E, 29, D6, A4, 82, 38...
 
[+]

Entropy:
7.9929  (probably packed)

Code size:
782 KB (800,768 bytes)

The file straight-talk-zte-merit-stock-rom_downloader.exe has been seen being distributed by the following URL.