كتاب سري للغاية للمؤلفة وداد لوتاه top....exe

SuperCharging

New IT Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application كتاب سري للغاية للمؤلفة وداد لوتاه top....exe by New IT Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from ds311.getafilefast.net.
Publisher:
SPC LLC  (signed by New IT Limited)

Product:
SuperCharging

Description:
DWD

Version:
3, 3, 29, 0

MD5:
91d22c1efc9002e2ea5b7ba33f011d80

SHA-1:
3e7479f6dc86a99e452498a09f470234bdd090de

SHA-256:
742d8e5d5d3b272137f6ae35f90c820186e589a29590c106d0cea7b2d4862276

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 12:14:39 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewITLimited.i
14.7.6.8

File size:
396 KB (405,520 bytes)

Product version:
3, 3, 29, 0

Copyright:
2013

Trademarks:
-

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\???? ??? ?????? ??????? ???? ????? top....exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
5/14/2014 5:00:04 AM

Valid to:
12/29/2016 11:33:53 PM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
049768F7F19C91

File PE Metadata
Compilation timestamp:
6/12/2014 5:45:08 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:pnegG/xIVb4quhA5kN5VDV1UTSBuqeHcO:pne9uVyr5VD3ULcO

Entry address:
0x2A2FC

Entry point:
E8, FB, A3, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 14, A1, 58, DD, 44, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 57, 8B, F1, 39, 1D, A4, F5, 44, 00, 75, 38, 53, 53, 33, FF, 47, 57, 68, 74, 2D, 44, 00, 68, 00, 01, 00, 00, 53, FF, 15, 58, 01, 44, 00, 85, C0, 74, 08, 89, 3D, A4, F5, 44, 00, EB, 15, FF, 15, C4, 00, 44, 00, 83, F8, 78, 75, 0A, C7, 05, A4, F5, 44, 00, 02, 00, 00, 00, 39, 5D, 14, 7E, 22, 8B, 4D, 14, 8B, 45, 10, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, 45, 14, 2B, C1...
 
[+]

Entropy:
6.7249

Code size:
248.5 KB (254,464 bytes)

The file كتاب سري للغاية للمؤلفة وداد لوتاه top....exe has been seen being distributed by the following URL.