vandalism extreme edition bot v5.3 setup.exe

The application vandalism extreme edition bot v5.3 setup.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from download1661.mediafire.com and multiple other hosts.
MD5:
c6008dadba9990fd52c77dd645bc5437

SHA-1:
716a625e09427272387f1a01210201a56b76a1ca

SHA-256:
a36ac61ae1e555ad913160f14e4ea8f85d8e2f69fcc2d3d7c650a2feecf8866e

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
12/25/2024 3:50:18 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
NSIS:InstMonetizer-AU [PUP]
2014.9-140903

Baidu Antivirus
Adware.Win32.InstallMonetizer
4.0.3.1493

Bkav FE
W32.Clod5f7.Trojan
1.3.0.4959

ESET NOD32
Win32/InstallMonetizer.AN
8.10306

McAfee
Artemis!C6008DADBA99
5600.7018

Trend Micro House Call
TROJ_GEN.R002H05H614
7.2.246

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
32496

File size:
4.7 MB (4,950,293 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\vandalism extreme edition bot v5.3 setup.exe

File PE Metadata
Compilation timestamp:
12/5/2009 7:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:bp6HmpWtCv7+WaUpZjFdeIIg/XZwlU4iX:l6HmQtCT+HUpDltXOqjX

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
1.8023

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file vandalism extreme edition bot v5.3 setup.exe has been seen being distributed by the following 11 URLs.

Remove vandalism extreme edition bot v5.3 setup.exe - Powered by Reason Core Security