{"id":2449,"date":"2014-10-27T19:33:00","date_gmt":"2014-10-27T19:33:00","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=2449"},"modified":"2018-05-29T12:01:55","modified_gmt":"2018-05-29T12:01:55","slug":"shetef-solutions-consulting-1998-ltd","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/shetef-solutions-consulting-1998-ltd\/","title":{"rendered":"Shetef Solutions &#038; Consulting (1998) Ltd. &#8211; 25% Detection Rate"},"content":{"rendered":"<p>Good evening! Lately I&#8217;ve been looking on the digital signatures on those files that push various types of unwanted programs. Right now\u00a0I found a new file called FlashPlayer__6741_i1387048386_il2537.exe, digitally signed by <strong>Shetef Solutions &amp; Consulting (1998) Ltd.<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Shetef-Solutions-Consulting-1998-Ltd..png\"><img loading=\"lazy\" class=\"alignnone wp-image-2452 size-full\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Shetef-Solutions-Consulting-1998-Ltd..png\" alt=\"Shetef Solutions Consulting 1998 Ltd Publisher\" width=\"490\" height=\"292\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Shetef-Solutions-Consulting-1998-Ltd..png 490w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Shetef-Solutions-Consulting-1998-Ltd.-300x178.png 300w\" sizes=\"(max-width: 490px) 100vw, 490px\" \/><\/a><\/p>\n<p>You can also look at the Shetef Solutions &amp; Consulting (1998) Ltd. certificate and digital signature by looking under the Digital Signatures tab on the file&#8217;s properties. According to the certificate, Shetef Solutions &amp; Consulting (1998) Ltd. is located in Rannana, Israel. The certificate appears to relatively new. Its validity began on the 13th of October.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Shetef-Solutions-certificate.png\"><img loading=\"lazy\" class=\"alignnone wp-image-2451 size-full\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Shetef-Solutions-certificate.png\" alt=\"Shetef Solutions certificate, Rannana, Israel\" width=\"509\" height=\"512\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Shetef-Solutions-certificate.png 509w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Shetef-Solutions-certificate-150x150.png 150w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Shetef-Solutions-certificate-298x300.png 298w\" sizes=\"(max-width: 509px) 100vw, 509px\" \/><\/a><\/p>\n<p>The issue here is that if FlashPlayer__6741_i1387048386_il2537.exe really was an installer file for Flash Player, it should have been digitally signed by <strong>Adobe System Incorporated<\/strong> and not by some unknown company. This looks suspicious.<\/p>\n<p>The <a href=\"http:\/\/www.freefixer.com\/b\/scan-files-for-viruses-virustotal\/\">VirusTotal<\/a> report shows that the Shetef Solutions &amp; Consulting (1998) Ltd. file should be avoided, since FlashPlayer__6741_i1387048386_il2537.exe is detected as <strong>Adware.Downware.8876<\/strong> by DrWeb, <strong>Gen:Variant.Graftor.161610<\/strong> by F-Secure and <strong>PUP.Optional.Amonetize<\/strong> by Malwarebytes.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Shetef-Solutions-Consulting-1998-Ltd.-virustotal.png\"><img loading=\"lazy\" class=\"alignnone wp-image-2450 size-full\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Shetef-Solutions-Consulting-1998-Ltd.-virustotal.png\" alt=\"Shetef Solutions &amp; Consulting (1998) Ltd. virustotal report\" width=\"745\" height=\"610\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Shetef-Solutions-Consulting-1998-Ltd.-virustotal.png 745w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/10\/Shetef-Solutions-Consulting-1998-Ltd.-virustotal-300x245.png 300w\" sizes=\"(max-width: 745px) 100vw, 745px\" \/><\/a><\/p>\n<p>Since the download was detected I decided to give it a try to see what it installed. During my test I could see Wajam, <a title=\"Salus Adware \u2013 \u201cAds by Salus\u201d Removal Instructions\" href=\"http:\/\/www.freefixer.com\/b\/remove-salus-adware\/\">Salus &#8211; Net Protector<\/a> and My Start Search install on my lab machine.<\/p>\n<p>Did you also find a file digitally signed by Shetef Solutions &amp; Consulting (1998) Ltd.? What kind of download was it and where did you find it?<\/p>\n<p>Thanks for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Good evening! Lately I&#8217;ve been looking on the digital signatures on those files that push various types of unwanted programs. Right now\u00a0I found a new file called FlashPlayer__6741_i1387048386_il2537.exe, digitally signed by Shetef Solutions &amp; Consulting (1998) Ltd.. You can also look at the Shetef Solutions &amp; Consulting (1998) Ltd. certificate and digital signature by looking &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/shetef-solutions-consulting-1998-ltd\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Shetef Solutions &#038; Consulting (1998) Ltd. &#8211; 25% Detection Rate<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[126,186,98],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2449"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=2449"}],"version-history":[{"count":4,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2449\/revisions"}],"predecessor-version":[{"id":2725,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/2449\/revisions\/2725"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=2449"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=2449"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=2449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}