3d-analyze_2.36_downloader.exe

Cheng Du VTools Information Technology

The application 3d-analyze_2.36_downloader.exe by Cheng Du VTools Information Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from www.8appstore.net. While running, it connects to the Internet address s1.instalki.kylos.net.pl on port 80 using the HTTP protocol.
Publisher:

MD5:
3de57f98648638c5ad336f802ba82144

SHA-1:
8d233218a1ef350861b393c9c0fe8b79045126ae

SHA-256:
740cdaac53e26590290f4d158d82b2d4e0ffddf0b2c3492155c83f83347c1134

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/2/2024 5:25:24 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ChengDuVToolsInformationTechnology (M)
16.3.2.5

File size:
781.8 KB (800,592 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\jurnalku\3d-analyze_2.36_downloader.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/11/2011 7:00:00 AM

Valid to:
1/26/2014 6:59:59 AM

Subject:
CN=Cheng Du VTools Information Technology, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Cheng Du VTools Information Technology, L=ChengDu, S=SiChuan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1B5D68E0AFA12E8F1159C668DD228431

File PE Metadata
Compilation timestamp:
8/2/2013 12:58:58 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:m5UnZzPkMXdh4JIc+GIQDDIDtEtVJF1ohHuT5ZJLSM0O:lzP34OcDcZEXJFepuJSMN

Entry address:
0x1CE6C0

Entry point:
60, BE, 00, 90, 53, 00, 8D, BE, 00, 80, EC, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
600 KB (614,400 bytes)

The file 3d-analyze_2.36_downloader.exe has been seen being distributed by the following URL.

http://www.8appstore.net/.../downloadfile.html?swid=629004

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to s1.instalki.kylos.net.pl  (195.162.24.170:80)

Remove 3d-analyze_2.36_downloader.exe - Powered by Reason Core Security