the singing zone_10924_i3419481_il345.exe

Ukra-2006 LLC

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application the singing zone_10924_i3419481_il345.exe by Ukra-2006 has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Ukra-2006 LLC  (signed and verified)

MD5:
802f734b9783ac4eb0ed9f5fea82179a

SHA-1:
964d53e7ed12a5ecc5fc2dd33577b39ea420e045

SHA-256:
3c330dd4a50474c147ddd673abcb5254b3cc95e34d60ab99989e1d67bcc12ebf

Scanner detections:
8 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/16/2024 8:35:38 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/Amonetize.kpa
7.11.189.36

AVG
Ukra
2015.0.3277

Dr.Web
Trojan.Amonetize.12
9.0.1.0331

G Data
NSIS.Application.Crypted
14.11.24

K7 AntiVirus
Unwanted-Program
13.186.14150

Reason Heuristics
PUP.Ukra2006.f
14.11.27.21

Sophos
Amonetize
4.98

VIPRE Antivirus
Trojan.Win32.Generic
35170

File size:
237 KB (242,696 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup (using Nullsoft Install System)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/30/2014 6:00:00 PM

Valid to:
7/1/2015 5:59:59 PM

Subject:
CN=Ukra-2006 LLC, O=Ukra-2006 LLC, L=Kharkiv, S=Harkivska obl, C=UA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2B3200D1AF3CAC4253C00F000EF4BAB9

File PE Metadata
Compilation timestamp:
10/6/2014 10:40:26 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:hGC7W7BU5zOMqKGqcUz9PbW7QQ8hhhPB40gQXOQqL:La7gzpqKGqP9DIapXvXOD

Entry address:
0x322E

Entry point:
81, EC, D8, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, 34, 81, 40, 00, 55, FF, 15, AC, 82, 40, 00, 6A, 09, A3, 78, 4F, 43, 00, E8, FD, 2E, 00, 00, A3, C4, 4E, 43, 00, 55, 8D, 44, 24, 38, 68, B4, 02, 00, 00, 50, 55, 68, D8, B1, 42, 00, FF, 15, 7C, 81, 40, 00, 68, C0, A2, 40, 00, 68, C0, 3E, 43, 00, E8, 68, 2B, 00, 00, FF, 15, 38, 81, 40, 00, BB, 00, F0, 43, 00, 50, 53, E8, 56, 2B, 00, 00...
 
[+]

Entropy:
7.8884

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file the singing zone_10924_i3419481_il345.exe has been seen being distributed by the following URL.

Remove the singing zone_10924_i3419481_il345.exe - Powered by Reason Core Security