wiz+khalifa+2014+28+grams_10924_i70618877_il345.exe

mingw-get

LLC BUDІMEKS

The application wiz+khalifa+2014+28+grams_10924_i70618877_il345.exe, “MinGW Installation Manager Setup Tool” by LLC BUDІMEKS has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
MinGW.org Project  (signed by LLC BUDІMEKS)

Product:
mingw-get

Description:
MinGW Installation Manager Setup Tool

Version:
0.6.2-beta-20131004-1

MD5:
9b0463b3d569fdeacf8b6746fb718db1

SHA-1:
42f46baaae677a0b33b7ccf2229dee6e79c2c549

SHA-256:
3b8d982fd02427de9ba98fec92f17cd84c1d07839251082b683c75dea17951d1

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/6/2024 7:42:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize.Bundler (M)
17.2.18.20

File size:
860.5 KB (881,168 bytes)

Product version:
0.6.2-beta-20131004-1

Copyright:
Copyright © 2009-2013, MinGW.org Project

Original file name:
mingw-get-setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\downloads\wiz+khalifa+2014+28+grams_10924_i70618877_il345.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/26/2015 7:00:00 PM

Valid to:
8/26/2016 6:59:59 PM

Subject:
CN=LLC BUDІMEKS, O=LLC BUDІMEKS, STREET=Cvitna 34, L=Gorodockey area Galichani vilage, S=Lvovskaja, PostalCode=81523, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E9F1B23ADDECC133378F48EBB20F9E3D

File PE Metadata
Compilation timestamp:
10/13/2015 6:12:49 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x1F8F61

Entry point:
68, CA, 6F, 3F, 81, E8, EB, 46, F4, FF, 68, 37, E8, 3F, E1, E8, E1, 46, F4, FF, 8B, 45, 18, 8A, FD, BF, 47, 0C, 50, 74, 87, DB, 8B, 5D, 20, 89, 54, 24, 2C, 66, BF, 68, 69, 66, F7, D7, 87, FF, 89, 54, 24, 28, 0F, CA, 87, D7, 8B, 55, 14, 0F, CF, 50, 8D, 7C, 24, 1C, E8, 40, F6, FC, FF, 2B, FF, 8D, 64, 24, 04, 85, E2, F6, C3, 35, 3B, C7, 0F, 85, A4, 00, 00, 00, 8B, 4D, 08, 99, 8B, C3, 8B, 5D, 1C, 99, 8B, 44, 24, 10, F6, D6, 99, 8B, 54, 24, 14, 89, 4C, 24, 2C, 8A, ED, F7, D1, B9, 01, 00, 00, 00, 53, 89, 4C, 24...
 
[+]

Entropy:
7.9349  (probably packed)

Code size:
846 KB (866,304 bytes)