trapcode particular 2.2__3516_i1312828357_il516432.exe

Ukra-2006 LLC

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application trapcode particular 2.2__3516_i1312828357_il516432.exe by Ukra-2006 has been detected as adware by 38 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Ukra-2006 LLC  (signed and verified)

Version:
1.1.8.22

MD5:
9bb57163ccadb1360f5fb689356e53a9

SHA-1:
e14cee5a22f2c6b6512a50f5cf60204ece753e2f

SHA-256:
c0f38c58fd74a616db5559ef2fd895f1c3be1923170e2373b3b527c69d4cc904

Scanner detections:
38 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 6:06:37 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Virtob.Gen.12
867

Agnitum Outpost
Win32.Virut.AB.Gen
7.1.1

AhnLab V3 Security
Win32/Virut.F
2014.09.17

Avira AntiVirus
ADWARE/Adware.Gen
7.11.172.136

avast!
Win32:PUP-gen [PUP]
2014.9-140918

AVG
Ukra
2015.0.3348

Baidu Antivirus
Adware.Win32.Amonetize
4.0.3.14918

Bitdefender
Win32.Virtob.Gen.12
1.0.20.1320

Bkav FE
W32.Vetor.PE
1.3.0.4959

Dr.Web
Win32.Virut.56
9.0.1.0264

Emsisoft Anti-Malware
Win32.Virtob.Gen.12
8.14.09.21.10

ESET NOD32
Win32/Amonetize.BO (variant)
8.10423

Fortinet FortiGate
W32/FakeAV.RQ!tr
9/21/2014

F-Prot
W32/Virut.E.gen
v6.4.6.5.141

F-Secure
Win32.Virtob.Gen.12
11.2014-21-09_1

G Data
Win32.Virtob.Gen.12
14.9.24

K7 AntiVirus
Virus
13.183.13393

Kaspersky
Virus.Win32.Virut
14.0.0.3218

Malwarebytes
PUP.Optional.Amonetize
v2014.09.18.02

McAfee
Artemis!9BB57163CCAD
5600.7004

Microsoft Security Essentials
Threat.Undefined
1.185.155.0

MicroWorld eScan
Win32.Virtob.Gen.12
15.0.0.792

NANO AntiVirus
Virus.Win32.Virut.hpeg
0.28.2.62151

Norman
Virut.HL
11.20140921

nProtect
Virus/W32.Virut.Gen
14.09.17.01

Panda Antivirus
W32/Sality.AO
14.09.21.10

Qihoo 360 Security
Virus.Win32.Virut.O
1.0.0.1015

Quick Heal
W32.Virut.G
9.14.14.00

Reason Heuristics
PUP.Installer.Ukra2006.r
14.9.18.2

Rising Antivirus
PE:Win32.Virut.cx!1553679
23.00.65.14919

Sophos
Amonetize
4.98

Total Defense
Win32/Virut.17408
37.0.11184

Trend Micro House Call
PE_VIRUX.S-3
7.2.264

Trend Micro
PE_VIRUX.S-3
10.465.21

Vba32 AntiVirus
Virus.Virut.14
3.12.26.3

VIPRE Antivirus
Threat.4120919
32938

ViRobot
Win32.Virut.AM
2011.4.7.4223

Zillya! Antivirus
Virus.Virut.Win32.1939
2.0.0.1925

File size:
404.2 KB (413,904 bytes)

Product version:
1.1.8.22

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Language:
English (United States)

Common path:
C:\users\{user}\downloads\trapcode particular 2.2__3516_i1312828357_il516432.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/30/2014 6:00:00 PM

Valid to:
7/1/2015 5:59:59 PM

Subject:
CN=Ukra-2006 LLC, O=Ukra-2006 LLC, L=Kharkiv, S=Harkivska obl, C=UA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2B3200D1AF3CAC4253C00F000EF4BAB9

File PE Metadata
Compilation timestamp:
9/10/2014 8:59:43 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:ta5Mqqub6lskGCEurlTA2xhDUykc8jmIB5T5OgW/dYc5pFcYXhf+Z2+2s:sMqp6ikqgRpxh+jmIjT56dP5pFlhk2+d

Entry address:
0x17610

Entry point:
E8, 8B, 84, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 3D, 94, AF, 3C, 00, 00, 75, 18, E8, A9, 7D, 00, 00, 6A, 1E, E8, F3, 7B, 00, 00, 68, FF, 00, 00, 00, E8, C3, F4, FF, FF, 59, 59, 8B, 45, 08, 85, C0, 75, 01, 40, 50, 6A, 00, FF, 35, 94, AF, 3C, 00, FF, 15, 60, 21, 3C, 00, 5D, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 94, AF, 3C, 00, 00, 75, 18, E8, 5F, 7D, 00, 00, 6A, 1E, E8, A9, 7B, 00, 00, 68, FF, 00, 00, 00, E8, 79, F4, FF, FF, 59, 59, 85, DB, 74, 04, 8B, C3...
 
[+]

Entropy:
7.2756

Code size:
192.5 KB (197,120 bytes)

The file trapcode particular 2.2__3516_i1312828357_il516432.exe has been seen being distributed by the following 4 URLs.