vuze plus activation code gene downloader__3687_i1323485018_il1935718.exe

Shetef Solutions & Consulting (1998) Ltd.

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application vuze plus activation code gene downloader__3687_i1323485018_il1935718.exe by Shetef Solutions & Consulting (1998) has been detected as adware by 43 anti-malware scanners. The program is a setup application that uses the Amonetize Downloader installer. According to AVG, this software downloads additional adware offers during setup.
Publisher:

Version:
1.1.5.26

MD5:
d220d272a1f8db28334a27b07049c7cc

SHA-1:
a4dc3da7882b2fe48d7b60e47e1ef7d834a02943

SHA-256:
74c8a0dea3fe150e03ada1c77cdb52333976cd2a43fd9f2d50f2c011b3e42378

Scanner detections:
43 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/5/2024 11:39:34 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Virtob.Gen.12
867

Agnitum Outpost
PUA.Amonetize
7.1.1

AhnLab V3 Security
PUP/Win32.Amonetize
2014.09.19

Avira AntiVirus
ADWARE/Adware.Gen
7.11.173.38

avast!
Win32:Vitro
2014.9-140921

AVG
Downloader.Generic14
2015.0.3346

Baidu Antivirus
Adware.Win32.Amonetize
4.0.3.14920

Bitdefender
Win32.Virtob.Gen.12
1.0.20.1320

Bkav FE
W32.Vetor.PE
1.3.0.4959

Dr.Web
Win32.Virut.56
9.0.1.0264

Emsisoft Anti-Malware
Win32.Virtob.Gen.12
8.14.09.21.10

ESET NOD32
Win32/Amonetize.BO (variant)
8.10440

Fortinet FortiGate
W32/FakeAV.RQ!tr
9/21/2014

F-Prot
W32/Virut.E.gen
v6.4.6.5.141

F-Secure
Win32.Virtob.Gen.12
11.2014-21-09_1

G Data
Win32.Virtob.Gen.12
14.9.24

K7 AntiVirus
Virus
13.183.13393

Kaspersky
Virus.Win32.Virut
14.0.0.3218

Malwarebytes
PUP.Optional.Amonetize
v2014.09.20.04

McAfee
W32/Virut.n.gen
5600.7001

Microsoft Security Essentials
Threat.Undefined
1.185.155.0

MicroWorld eScan
Win32.Virtob.Gen.12
15.0.0.792

NANO AntiVirus
Riskware.Win32.Amonetize.dffaha
0.28.2.62151

Norman
Virut.HL
11.20140921

nProtect
Virus/W32.Virut.Gen
14.09.17.01

Panda Antivirus
W32/Sality.AO
14.09.21.10

Qihoo 360 Security
Virus.Win32.Virut.O
1.0.0.1015

Quick Heal
W32.Virut.G
9.14.14.00

Reason Heuristics
PUP.Installer.ShetefSolutionsConsulting1998.?
14.9.20.4

Rising Antivirus
PE:Win32.Virut.cx!1553679
23.00.65.14919

Sophos
Generic PUA KE
4.98

Total Defense
Win32/Virut.17408
37.0.11184

Trend Micro House Call
PE_VIRUX.S-3
7.2.264

Trend Micro
PE_VIRUX.S-3
10.465.21

Vba32 AntiVirus
Virus.Virut.14
3.12.26.3

VIPRE Antivirus
Threat.4120919
32938

ViRobot
Win32.Virut.AM
2011.4.7.4223

Zillya! Antivirus
Virus.Virut.Win32.1939
2.0.0.1925

File size:
404.3 KB (414,000 bytes)

Product version:
1.1.5.26

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Amonetize Downloader

Language:
English (United States)

Common path:
C:\users\{user}\downloads\vuze plus activation code gene downloader__3687_i1323485018_il1935718.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/19/2014 7:00:00 PM

Valid to:
8/19/2015 6:59:59 PM

Subject:
CN=Shetef Solutions & Consulting (1998) Ltd., O=Shetef Solutions & Consulting (1998) Ltd., L=Raanana, S=Raanana, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4F0762A0FB4E2EA75260E9E77B74473E

File PE Metadata
Compilation timestamp:
9/10/2014 9:59:43 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:ka5Mqqub6lskGCEurlTA2xhDUyEu3wcZSepI8A/4S09GR2o:VMqp6ikqgRpxh3E09GRF

Entry address:
0x17610

Entry point:
E8, 8B, 84, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 3D, 94, AF, 3C, 00, 00, 75, 18, E8, A9, 7D, 00, 00, 6A, 1E, E8, F3, 7B, 00, 00, 68, FF, 00, 00, 00, E8, C3, F4, FF, FF, 59, 59, 8B, 45, 08, 85, C0, 75, 01, 40, 50, 6A, 00, FF, 35, 94, AF, 3C, 00, FF, 15, 60, 21, 3C, 00, 5D, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 94, AF, 3C, 00, 00, 75, 18, E8, 5F, 7D, 00, 00, 6A, 1E, E8, A9, 7B, 00, 00, 68, FF, 00, 00, 00, E8, 79, F4, FF, FF, 59, 59, 85, DB, 74, 04, 8B, C3...
 
[+]

Entropy:
7.2757

Code size:
192.5 KB (197,120 bytes)

The file vuze plus activation code gene downloader__3687_i1323485018_il1935718.exe has been seen being distributed by the following 4 URLs.