walking dead_10924_i6233441_il345.exe

Ukra-2006 LLC

This is the Amonetize download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application walking dead_10924_i6233441_il345.exe by Ukra-2006 has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Ukra-2006 LLC  (signed and verified)

MD5:
4dd5dc9a0786a9b1d430e9d4cf221f07

SHA-1:
6a1767c5b1168fd88f296d6705dc6b9b74a75156

SHA-256:
03ef78914c0b114ee66d1590470591ff9f24dd8d58eaccc705e366199144fa41

Scanner detections:
11 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/16/2024 8:33:20 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/Amonetize.kpa
7.11.197.26

AVG
Generic
2015.0.3253

Clam AntiVirus
Win.Adware.Amonetize-511
0.98/19817

Dr.Web
Trojan.Amonetize.12
9.0.1.05190

G Data
NSIS.Application.Crypted
14.12.24

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Amonetize
14.0.0.2761

Panda Antivirus
Generic Suspicious
14.12.21.06

Reason Heuristics
PUP.Ukra2006.b
14.12.21.18

Sophos
PUA 'Amonetize'
5.09

Trend Micro House Call
Suspici.1CC0D1BF
7.2.355

VIPRE Antivirus
Threat.4150696
35418

File size:
303.5 KB (310,736 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\walking dead_10924_i6233441_il345.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/1/2014 1:00:00 AM

Valid to:
7/2/2015 12:59:59 AM

Subject:
CN=Ukra-2006 LLC, O=Ukra-2006 LLC, L=Kharkiv, S=Harkivska obl, C=UA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2B3200D1AF3CAC4253C00F000EF4BAB9

File PE Metadata
Compilation timestamp:
10/7/2014 5:40:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:RGC7W7BU5pMqKGqcUz9PbTAb7EkTY6gOTsCl3CG/JXHN3GP2IEZydt:7a7giqKGqP9DcgWBgDDG/pHN3GkC

Entry address:
0x322E

Entry point:
81, EC, D8, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, 34, 81, 40, 00, 55, FF, 15, AC, 82, 40, 00, 6A, 09, A3, 78, 4F, 43, 00, E8, FD, 2E, 00, 00, A3, C4, 4E, 43, 00, 55, 8D, 44, 24, 38, 68, B4, 02, 00, 00, 50, 55, 68, D8, B1, 42, 00, FF, 15, 7C, 81, 40, 00, 68, C0, A2, 40, 00, 68, C0, 3E, 43, 00, E8, 68, 2B, 00, 00, FF, 15, 38, 81, 40, 00, BB, 00, F0, 43, 00, 50, 53, E8, 56, 2B, 00, 00...
 
[+]

Entropy:
7.9238

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file walking dead_10924_i6233441_il345.exe has been seen being distributed by the following URL.

Remove walking dead_10924_i6233441_il345.exe - Powered by Reason Core Security