worms-armageddon-programas-gratis-net.exe

Installer Internet Web

AgileMax (New Media Holdings Ltd.)

The application worms-armageddon-programas-gratis-net.exe, “Installer Internet Web Setup ” by AgileMax (New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.bundlecentralbulk.com and multiple other hosts.
Publisher:
Software   (signed by AgileMax (New Media Holdings Ltd.))

Product:
Installer Internet Web

Description:
Installer Internet Web Setup

Version:
3.4.4.8

MD5:
5f4a4c28f1d15ab026bceace2f9bcd12

SHA-1:
8aba297a3a973f1bef237af5845578cac801ef1d

SHA-256:
f142a216cab4526fe1c8afe889fd09fc3987b2f000951bd05815c2d9ac2de24a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/24/2024 10:15:35 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.Installer.Installer (M)
16.1.8.15

File size:
958.3 KB (981,304 bytes)

Product version:
3.1.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\worms-armageddon-programas-gratis-net.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 5:04:31 AM

Valid to:
10/30/2016 8:53:45 AM

Subject:
CN=AgileMax (New Media Holdings Ltd.), O=AgileMax (New Media Holdings Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112186313590F7C0AF7C143BC6BDE6200476

File PE Metadata
Compilation timestamp:
6/19/1992 4:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:/KSxgTgYTb5VISBjR4+UL5WwuLCv9yUQ3YuEjHyq8pU:/reTgmVVH/U9WwWCv9yJ3aZI

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9306

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file worms-armageddon-programas-gratis-net.exe has been seen being distributed by the following 50 URLs.

http://www.bundlecentralbulk.com/c?x=n7mqJAFIcykZo8BQKBu1UNAyw9vBc3tj SIHHPn/Eus=&c=YCQ8jPU2Bjdi6EsmNh2fCpPAEkQ2wvJ5fkWvk7jooipjhlFY02K2CuK7L21ojVOsb5DOqHFX5A0bPpJ0DQqY58cqeXaWKaUNj15S0VT/89kTWpBukweW72jBu51RC40MFfWGERw717E4WXkdO2WZ3RH8rzMYfDtF4OYv5SeP/FA=&e=0&downloadAs=worms-armageddon-programas-gratis-net.exe&fallback_url=http://.../Worms-Armageddon.exe

http://www.besttoursvaults.com/c?x=CpQQ8jGaT0/An1Iu3JGm aX0x2dsrGl6/SclfDl EuI=&c=dQlkp4V7MUjSoMBpH5Kr3jpFfRkZ/gYPaAiBrr jDbAUqckblIpUrXD0H2j10KbMDK9ZmnGyXuMf6i9oiv9KE247G4i19YzkfeRFDQmyJcdTWv8Hgh3CE43OCLVLjs87hO1VTZd41xvUfKoJb 94 GuDWyLpBebu97aJ14Y8qCw=&e=0&downloadAs=worms-armageddon-programas-gratis-net.exe&fallback_url=http://.../Worms-Armageddon.exe

http://www.sendtowersnew.com/c?x=780ZZ5AY Qf7lWFmL8ebjQZH5wl8YlIbimYhxNMy/PA=&c=msWE2BudogRNcBgLrxOWl0MaKQ5aTCeojSAaTERW3PdpErMcg8L3uhqYbY1 ze2INatS2/na3hjrCrU8njvjva kV5/vm1khaWwvZso4wUkg/CiOf/yywBsf1xG/ZN 7wTvf77ty2LNoTqguZYelnz/6HmVYHpmVgt2T5sVfYP4=&e=0&downloadAs=worms-armageddon-programas-gratis-net.exe&fallback_url=http://.../Worms-Armageddon.exe

http://www.sendtowersnew.com/WVl6OTRQVkZYYldsNFN6Z3pja1JGU0VsMmFpVXlRbmhwUTNkeldXUk5aV3hwVlVZMWExVnlNWEpWVms5d1dqQlJRU1V6UkNaalBWUjNhbEIxSlRKR1NsQlVSMUJxZDJFd05FUTFSMDEzVm13d1RubGhWemRpV21wNFRYVm9jVXQwUkRFbE1rSWxNa0pKWlVock4yUmtRMWR1UjBOd1RGWmhVRTR5UkdNNVRYTnpjV1Z2VW1GVmJsZDRKVEpDWkVsWk9UaGFWRU01UldwUE5Xb2xNa1l3UWs1bVJWSm9kMFZ0ZFZwb2RuUk1UV2xyZG5VM1Z6WkRkRFpNUW1KMlNqYzBibmR1UkV0WWNFeHBaazlaT1dkRFIybzJPVzFHV2xFbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlkMjl5YlhNdFlYSnRZV2RsWkdSdmJpMXdjbTluY21GdFlYTXRaM0poZEdsekxXNWxkQzVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtabWFXeGxjeTVrYjNkdWJHOWhaSEJ5YjJkeVlXMWhjeTVqYjIwbE1rWlhiM0p0Y3kxQmNtMWhaMlZrWkc5dUxtVjRaUT09

http://www.giftbulkstock.com/WVl6OTRQVmQwYkRGd09HVkxURWxTTWtWWU5XNXhSV2hLSlRKQ2FISlRlVEI1VVdSdlIxb2xNa0pWVkc5T05rVnlNRGRaSlRORUptTTlaekZPTkc1c1QzTktZMlUyWkZwRVZHcGxUbVpzVEhoU1pWVXhSbVUzT1c4MGNsZHdOazlaVGtaVU5qZHpWRGQ1WW14NVdHSklabFJZVGtzd1RGaDZPRU5qZDJWTmJFNUtRMWc1ZFdsd1Rsb2xNa1pQVmpWWmRXWXhUblUzSlRKR1JEUjRSM050Y3pGMFoxVXdRbEJxUmxCS1kyOVlVMjV5VTBjeGNsazRabWc1WkdWdVYzcFNNU1V5UW0xMVRuZHBObEJIWTNwaFdpVXlSbEZQY2tFbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlkMjl5YlhNdFlYSnRZV2RsWkdSdmJpMXdjbTluY21GdFlYTXRaM0poZEdsekxXNWxkQzVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtabWFXeGxjeTVrYjNkdWJHOWhaSEJ5YjJkeVlXMWhjeTVqYjIwbE1rWlhiM0p0Y3kxQmNtMWhaMlZrWkc5dUxtVjRaUT09

http://www.sendtowersnew.com/c?x=Z7P5Bh50HwWDOcZ4/5jlVDy7ub palcW35UYVbA53eU=&c=rFpDIvXD5HMLZWSgT/RYDkfLBhnSWhUrTcTsUmVIIekGLmowUSZbXEKvBsrlWCMeTS63aW4aRhsCcgwfRQC7ReHdQIv/v 6VkH4q8cwKXcLoEQB3gqhlqVBY9ecYqUQzV9APyVKevI2Hp0Onp4baBkm/kbOZfvLP4tIpP5yKyySlP2SF5bBhyf2eJJDyR9p7&e=0&downloadAs=worms-armageddon-programas-gratis-net.exe&fallback_url=http://.../Worms-Armageddon.exe

http://www.farmflashtour.com/c?x=82namvlzle33ZWrPyXImODfck6O7DFce Mff3yGX5IU=&c=yWmaMXq2WdLpk8HDGUfLC3yqq0qT/pfDit74F1IuUrEgh1x pFG7mXieQ6cSCGq4tPmqt0DCcM47Ok4RJVuab86yo07BszkNnByk1SkyAnuGPT7qUouRW0vU6vWad5Df1/SqhUJECtbtI/u0OhXY45duTgKgEz5HMpv0C7KhCFlijo/WVAem9jJOxUqkzKGx&e=0&downloadAs=worms-armageddon-programas-gratis-net.exe&fallback_url=http://.../Worms-Armageddon.exe

http://www.sendtowersnew.com/c?x=cAeyrZeW67xrvPHGBwkm9hm88Es 5fLmdEvQyewFWlE=&c=96mi1SSOgwad8bV4aL/Fr1O3rNog0mxg2wMqFesKZ/1M ZXTy6U1u7qc8fN8UvoGDHNtn0h2ibklwZyB5QyziQ3ECIiF/Ytu6qNTe76jEdkCITdlBJG62971aRGAnB4Zb7N3M5rw1px6ppG6quspKf6wtVE6SWpRVaaN7vafP74=&e=0&downloadAs=worms-armageddon-programas-gratis-net.exe&fallback_url=http://.../Worms-Armageddon.exe

http://www.bundlecentralbulk.com/WVl6OTRQVk5wY0ZSSGRXeHpTRmR6T0VscGVtVkxabE5ZYlZCR05ESmpWREI2TjBVNVNTVXlSalZ5VDJwaWJWRnpNQ1V6UkNaalBURjJhekpDUzFONFJsRkdTWFZSZUhSaWJ6Uk1SVVpaWmtFNFVFNDVVbTlVWkVkVE56SkVSRkJETTNKRmEzRkVOSEpxWkZoQ05uVXpSVGQ0ZUZCMmVVOWpiSEpqVDFGcVluRndSSFZCYmlVeVJraGhKVEpDVkRNemR6VnZRamRsUVVWVFRHdFRjVTFTZW1GSFlqRXdiWEFsTWtKbFdsRmFNRlpLVEhWd1dpVXlSakJtYTAxMmNIWkVjekJRTlVsclNUQkxNM1IxYVRCSmNFbE5lSHAzSlRORUpUTkVKbVU5TUNaa2IzZHViRzloWkVGelBYZHZjbTF6TFdGeWJXRm5aV1JrYjI0dGNISnZaM0poYldGekxXZHlZWFJwY3kxdVpYUXVaWGhsSm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROQkpUSkdKVEpHWm1sc1pYTXVaRzkzYm14dllXUndjbTluY21GdFlYTXVZMjl0SlRKR1YyOXliWE10UVhKdFlXZGxaR1J2Ymk1bGVHVT0=

Latest 30 of 66 download URLs

Remove worms-armageddon-programas-gratis-net.exe - Powered by Reason Core Security