18_wheels_of_steel_across_america.rar_48y7w.exe

ROSA LTD

The application 18_wheels_of_steel_across_america.rar_48y7w.exe by ROSA has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from up1.nhksoftware.net.
Publisher:
Ros Digit Soft  (signed by ROSA LTD)

Description:
installer.exe

Version:
24.4.2.43

MD5:
2a72a8272e659faf4504cafe97584e49

SHA-1:
0390b5c6f4675036fb5368d1c8998056398624c7

SHA-256:
b7810354949e150a3da2b245f81f5d1b98bbb8626aaa419b9791205e98353b96

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/16/2024 10:35:02 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.8.10.1

File size:
2.1 MB (2,174,976 bytes)

Product version:
1.0.0.0

Copyright:
Copyright 2014 Ros Digit Soft.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\18_wheels_of_steel_across_america.rar_48y7w.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/25/2014 9:00:00 PM

Valid to:
9/26/2015 8:59:59 PM

Subject:
CN=ROSA LTD, O=ROSA LTD, STREET=d. Nikulino, L=Moskovskaya obl, S=Kashirskiy rayon, PostalCode=142947, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
40D688E49E139BC003BC9099C5B15BCA

File PE Metadata
Compilation timestamp:
10/13/2014 8:59:08 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:/fMZAPGUBU2Otbo5DHzxalU8AsQRyc3kGn5Jx9:/UZEGUW2iM5rzxIURRUG5Jx9

Entry address:
0x2CD14

Entry point:
55, 89, E5, 81, EC, 44, 01, 00, 00, 89, D9, 8D, 35, E6, 15, 00, 00, 68, 2A, 57, 42, 00, E8, D6, 95, FF, FF, 5D, 5F, 5E, 3B, DE, 75, 13, 40, 41, 3D, 48, 73, 43, 00, 77, 15, E8, D3, 41, FF, FF, 8B, F0, 8D, 4D, C4, E8, 70, 74, FD, FF, 8B, 80, 98, 00, 00, 00, 89, 46, 04, 5E, 33, C9, 88, 5D, FC, C6, 45, FD, 00, 41, 89, 4D, CC, EB, F0, 3B, 4D, 14, 73, F1, 88, 07, 83, C7, 01, 38, 07, 75, E8, 68, 04, 72, 43, 00, 8D, 4D, D4, E8, 82, 0F, FF, FF, 8B, 45, 88, EB, 05, 83, C8, FF, 33, D2, 58, 66, 89, 03, 8B, 07, 8A, 4D...
 
[+]

Code size:
200 KB (204,800 bytes)

The file 18_wheels_of_steel_across_america.rar_48y7w.exe has been seen being distributed by the following URL.