while visiting adfly links a forced file download occurs for a file [RapidFiles]id_42016.zip .
SHA256: 79eafd32d2c2775882510bb87d85df7793d74e5994e7a27dd9b12e39468bd7e4
File name: [RapidFiles]id_42016.zip
Detection ratio: 1 / 59
Analysis date: 2017-03-21 13:07:35 UTC ( 45 minutes ago )
Analysis result (1 warning) :
Invincea virus.win32.ramnit.p 20170203
File details :
MIMEType application/zip
ZipRequiredVersion 20
ZipCRC 0x1eae1fbd
FileType ZIP
ZipCompression Deflated
ZipUncompressedSize 1262592
ZipCompressedSize 1033521
FileTypeExtension zip
ZipFileName [RapidFiles]id_42016.exe
ZipBitFlag 0
ZipModifyDate 2017:03:21 15:12:13
File identification
MD5 d2de0d1e40dc25493089a9f7941fca19
SHA1 e48b8a59e19a2e382e067f32e859152d8483cc9a
SHA256 79eafd32d2c2775882510bb87d85df7793d74e5994e7a27dd9b12e39468bd7e4
ssdeep24576:APXj5c5lxbKXvwGj2FJ1BqNFK2L4QRh7LOHeAEBB3ebIU7:APT5wxbI4YyrBq7zRhHOHna3ebIU7
File size 1009.5 KB ( 1033703 bytes )
File type ZIP
Magic literalZip archive data, at least v2.0 to extract
TrID ZIP compressed archive (100.0%)
Portable Executable 1
Contained files
This file is a compressed stream containing 1 file.
- [RapidFiles]id_42016.exe Portable Executable 1262592 Bytes
SHA256 ce9dd5f8fbb3e7599b61879e3eabd46958a6b8f403964ef4085bb40c32107b7e
Datetime 2017-03-21 15:12:26
Detection ratio 7 / 61 when this report was generated
Sending this packed file on Virus Total website returns only 1 warning as virus.win32.ramnit.p
Be careful people and don't open nor unpack nor start to instal suspicious forced downloaded files ,just send it to recycle bin and delete permanently .
The file itself is not so dangerous (1/59 warnings) but be careful next time, also exe files could call for a server for getting additional instructions.