strongholdkingdomshack__7934_il398199.exe

The application strongholdkingdomshack__7934_il398199.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from v4securedownload.com.
MD5:
bee2ff91cf9616c76a76fb66f7326db7

SHA-1:
b52874bc5b596e303b9fcbaa2c8458932448e882

SHA-256:
df286f727730cff9c74d693e6ad4754ba37a375b6157a0530af83bdac6876997

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/13/2025 2:38:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Amonetize
16.2.21.3

File size:
1.1 MB (1,181,900 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\strongholdkingdomshack__7934_il398199.exe

File PE Metadata
Compilation timestamp:
1/31/2016 5:13:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:Gd/FdUkDZ9UVVrR2hHGnz+bnkOuX2KWR7JM8l0WfF:QDZyaGnK5YO0+

Entry address:
0x7017

Entry point:
E8, B3, 34, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, A8, 27, 41, 00, FF, 15, 24, D0, 40, 00, 85, C0, 75, 18, 56, E8, 47, 23, 00, 00, 8B, F0, FF, 15, 20, D0, 40, 00, 50, E8, F7, 22, 00, 00, 59, 89, 06, 5E, 5D, C3, 8B, FF, 55, 8B, EC, 8B, C1, 8B, 4D, 08, C7, 00, 18, E2, 40, 00, 8B, 09, 89, 48, 04, C6, 40, 08, 00, 5D, C2, 08, 00, 8B, 41, 04, 85, C0, 75, 05, B8, 20, E2, 40, 00, C3, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 57, 8B, F9, 74, 2D, 56, FF, 75, 08...
 
[+]

Code size:
45.5 KB (46,592 bytes)

The file strongholdkingdomshack__7934_il398199.exe has been seen being distributed by the following URL.

Remove strongholdkingdomshack__7934_il398199.exe - Powered by Reason Core Security