Threat Database Adware Adware.DealPly.I

Adware.DealPly.I

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 10,166
Threat Level: 20 % (Normal)
Infected Computers: 2,959
First Seen: October 27, 2019
Last Seen: April 18, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Adware.DealPly.I
Signature status: No Signature

Known Samples

MD5: 56e5500cf3a7d6f1dfabc39a14986caf
SHA1: 631a780c301bfd9b17ebed48df3918f4f843c8d0
SHA256: 36F01E824B64A086AD67CD72B490FDEF7262D36F0DD2C6E8664DD7D8552E8E59
File Size: 184.32 KB, 184320 bytes
MD5: 273656b40c2b7a79ef548eab2b96c96a
SHA1: 4c836a7e94bade78aadc131c691e0489b5f836ad
SHA256: 085920FD0F12B9055C576B2009E857EAC1D878B208B70C204DEA0DD494846D84
File Size: 296.96 KB, 296960 bytes
MD5: 5dc7a2402ef51d178fc1973ca9bcf627
SHA1: 9eb408c308dc7ba47d8a81cf9b01ee1cbe1b9e08
SHA256: 36399FF41862DFE4625F1E22158563A8FD1C67A84EE23389A87CBB70E2540123
File Size: 388.61 KB, 388608 bytes
MD5: e3d8b1e40fffe50cdca76156848723c7
SHA1: bba3a7d17d80ae9bbcd91a97e237ac1dc4b77992
SHA256: 67EB6D66F55F2723F4007BB554A77E01489FE4FD8023BDE57CEA17CBD6F04900
File Size: 291.33 KB, 291328 bytes
MD5: 4096ee66dd3f5587f6f173229062574e
SHA1: da84e0fbc4ff9c7a9a72a44ec05f5dad3601f9c3
SHA256: EEB1595812CC430315710E99AC1A8806B8790C12361952221DC35A78F31ADCB4
File Size: 372.22 KB, 372224 bytes
Show More
MD5: f0f6404cca190a7ed4a92f21f3038f97
SHA1: bfcceeaa80b1b222dc91b570f53077e87ed59962
SHA256: A94EF75672B2B248D5CCFC702E43CD4BD28457D080982E05A5FC85256259660D
File Size: 300.03 KB, 300032 bytes
MD5: 7bbdeb42579fb59faa365afed65fe9e8
SHA1: c281a9b9c8736153ae03af330edfdd7401ea7069
SHA256: 22DA07E981DDAA3B39A7F997921A8F9DDEE22D1A2B1A52C6ADBC669E3AECD343
File Size: 364.03 KB, 364032 bytes
MD5: 513ed1ea0354479bc305bf0edfbaf0c6
SHA1: 29496dc25dc2d5a3162b6798de6cab9e686ee6f4
SHA256: EAAA301CA7E621A86E7BF17445B54EC74BA1A51FFE1DE110FF4AE40BD32A6218
File Size: 372.22 KB, 372224 bytes
MD5: cf1e809dacd6e3e8c3f58b9430f99e1c
SHA1: 7858c431c23db0385aafda8c4eccf955a23a31a9
SHA256: 2A9470B041649C4393756AD23A3EB6C009FC6C9DE319314FC72F2FDE785B3D9D
File Size: 376.32 KB, 376320 bytes
MD5: 3309417a2d6ec33ae10e77d703469a29
SHA1: 0d0999202874bbcbfd26f7cbcc29876256847f64
SHA256: EC7C7AA30B68D336E880D31BD8C03BDECB6A906DBE9C4193814D87561662E8F7
File Size: 364.03 KB, 364032 bytes
MD5: caa21a136b644f3e4a9061b507b07ae1
SHA1: 18289b83718fa58a6b55f3bd5e7b0008a3d24040
SHA256: 98F28E6E7BB1C0A22AADB36E52C11BD79833E1B474612680E22BBA8F8B162EE0
File Size: 297.47 KB, 297472 bytes
MD5: cbf61237ce190bfaab322e851471cb10
SHA1: 19e37f5ab318428e0d267213924a1047e5ee30b4
SHA256: E2E88262CCCD1CEE225F3320DA824609C9D8C396A80A5C92AF57A23EC34CEA60
File Size: 377.86 KB, 377856 bytes
MD5: 881dd84701c1f82dd02678703b62266b
SHA1: 5799767dc25e906c8b17f3c1644b004b98c1556d
SHA256: 30C2BCB62950141C2F020C6EEC5E15B38BA9327ADDE7402274E53EADE1173068
File Size: 298.50 KB, 298496 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Cafosap Ltd.
  • Casah Ltd.
  • Corogagah
  • Domete Ltd.
  • Gebira
File Description
  • Cabebu
  • Capirut Gacuma
  • Hufod
  • Kobagat
  • Lakes Rolelom
File Version
  • 2.6.41.61
  • 2.2.18.78
  • 1.7.37.13
  • 1.4.43.48
  • 1.2.14.9
Internal Name
  • Babir
  • Galof
  • kegepnebali
  • tinofumreman
  • Tona
Legal Copyright
  • Casah Ltd. © 2011-2017 All Rights Reserved
  • Copyright 2011-2016
  • Corogagah 2011-2017
  • Domete Ltd. © All Rights Reserved
Legal Trademarks
  • 2011-2015
  • Casah Ltd. trademark 2012-2015
  • Gebira trademark
Original Filename
  • babirsikobot.exe
  • GalofKafi.exe
  • kegepnebali.exe
  • tinofumreman.exe
  • tona.exe
Product Name
  • Camer Kumikene
  • Dikehep 83 Ricomaned
  • Nalinog Lebada 13
  • Ronahodeg
  • Sofedeneg Mehiha
Product Version
  • 2.6.28.99
  • 2.3.35.22
  • 2.1.40.3
  • 1.8.24.32
  • 1.3.40.95

File Traits

  • No Version Info
  • x86

Block Information

Total Blocks: 1,398
Potentially Malicious Blocks: 3
Whitelisted Blocks: 1,383
Unknown Blocks: 12

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? x ? ? x ? x ? 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.HJG
  • BadJoke.TH
  • BadJoke.XA
  • Banload.NB
  • Banload.XA
Show More
  • Banload.XN
  • Gamehack.PDFA
  • Injector.DFF
  • Kagee.A
  • Lamer.B
  • Nanobot.MB
  • Proleeg.A
  • Sednit.D
  • Trojan.Downloader.Gen.FD
  • Trojan.Downloader.Gen.KL
  • Trojan.Downloader.Gen.MK
  • Trojan.Filecoder.Gen.BM
  • Trojan.Kryptik.Gen.FJ
  • Trojan.Kryptik.Gen.MM

Trending

Most Viewed

Loading...