tanya tate casting couch.exe

The application tanya tate casting couch.exe has been detected as a potentially unwanted program by 20 anti-malware scanners. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from homela.net and multiple other hosts.
MD5:
b31dcbc44a21e003dce2f82d3ed8acf0

SHA-1:
1bfc6e3c2e63e7a655250713815bc34ed2d626e9

SHA-256:
b8cfe06d4fed6397bea3880a8e6bd2bde9d086bcaa0ffae7071e4cca334119f2

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 11:38:44 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.IF
6196279

AhnLab V3 Security
PUP/Win32.MultiPlug
2014.12.20

Avira AntiVirus
ADWARE/MultiPlug.Gen7
7.11.196.210

avast!
Win32:PUP-gen [PUP]
141214-1

AVG
Adware Generic6.EU
2014.0.4235

Bitdefender
Application.Bundler.IF
1.0.20.1765

Bkav FE
HW32.Packed
1.3.0.6267

Comodo Security
Application.Win32.Multiplug.CT
20413

Emsisoft Anti-Malware
Application.Bundler.IF
9.0.0.4668

ESET NOD32
Win32/Adware.MultiPlug.DZ application
7.0.302.0

F-Prot
W32/A-b5918a94
v6.4.7.1.166

F-Secure
Riskware.Application.Bundler.IF
5.13.68

G Data
Application.Bundler.IF
14.12.24

K7 AntiVirus
Unwanted-Program
13.188.14380

Kaspersky
not-a-virus:AdWare.Win32.MultiPlug
15.0.0.543

McAfee
Program.MultiPlug-FTA
16.8.708.2

MicroWorld eScan
Application.Bundler.IF
15.0.0.1059

NANO AntiVirus
Riskware.Win32.MultiPlug.djilsw
0.28.6.64267

Norman
Application.Bundler.IF
04.12.2014 14:30:06

Vba32 AntiVirus
AdWare.MultiPlug
3.12.26.3

File size:
976.5 KB (999,936 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\tanya tate casting couch.exe

File PE Metadata
Compilation timestamp:
9/23/2012 9:16:24 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:7iAwyi4lMs41ratmtgl7NuroqpqsyH8N+rKLh24Sd8SsP9d0LdkmWcbgZr:mA1l1CatJs0Iq9H+tLh2t7GOfTbgZr

Entry address:
0x42737

Entry point:
E8, 20, 39, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 60, 34, 4F, 00, E8, 53, 11, 00, 00, E8, ED, 3A, 00, 00, 0F, B7, F0, 6A, 02, E8, B3, 38, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, C3, 09, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.2554

Code size:
296.5 KB (303,616 bytes)

The file tanya tate casting couch.exe has been seen being distributed by the following 2 URLs.

Remove tanya tate casting couch.exe - Powered by Reason Core Security