tekkit.exe

premium

New IT Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application tekkit.exe by New IT Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from ds322.maxiget.com.
Publisher:
C  (signed by New IT Limited)

Product:
premium

Description:
DWD

Version:
3, 2, 1, 0

MD5:
cda12974038207233c5b8a6a6a31ba10

SHA-1:
e75796f94071af5f29fda2914612edc3b6030893

SHA-256:
e1ca8436d4ed183d04a093fb1adc1df6b66e10bfcd860de40f80d9a25e2c6302

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 3:47:27 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.New IT Limited (M)
16.8.10.19

File size:
341 KB (349,152 bytes)

Product version:
3, 2, 1, 0

Copyright:
2014

Trademarks:
-

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\tekkit.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
12/30/2013 9:33:53 AM

Valid to:
12/30/2016 9:33:53 AM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
04225A281DFF69

File PE Metadata
Compilation timestamp:
2/17/2014 3:46:30 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:Nt5WQy5TMl32oIt6drRgbZX5LNUdwHJWTP6WRpptwB2:N7W2V2hOrRgldNUCMDNRpptA

Entry address:
0x1D304

Entry point:
E8, 43, 8B, 00, 00, E9, 78, FE, FF, FF, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D, 41, FE, 8B, 4C, 24, 04...
 
[+]

Entropy:
6.5269

Code size:
192 KB (196,608 bytes)

The file tekkit.exe has been seen being distributed by the following URL.

Remove tekkit.exe - Powered by Reason Core Security