3d_instruktor_novoe_leto_2015.exe-torrent.exe

CAPITAL SOFTWARE CONSULTANCY LTD

The application 3d_instruktor_novoe_leto_2015.exe-torrent.exe by CAPITAL SOFTWARE CONSULTANCY has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from s36f.storage.yandex.net.
Publisher:
CAPITAL SOFTWARE CONSULTANCY LTD  (signed and verified)

MD5:
3944773abbfe6547498e93ffa82ebd8b

SHA-1:
ed6a21825a928129eddcebf0ae40bde71ce6f742

SHA-256:
46eef647b58a524aa6ff8b229cfbba9ace2950ad213796854089d350d70b8137

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
2/25/2025 3:02:22 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.CAPITALSOFTWARECONSULTANCY (M)
16.2.24.16

File size:
2 MB (2,064,584 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\3d_instruktor_novoe_leto_2015.exe-torrent.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/10/2015 4:00:00 AM

Valid to:
11/10/2016 3:59:59 AM

Subject:
CN=CAPITAL SOFTWARE CONSULTANCY LTD, O=CAPITAL SOFTWARE CONSULTANCY LTD, POBox=CF23 8SL, STREET=58 Cranbourne Way Pontprennau, L=Cardiff, S=South Glamorgan, PostalCode=CF23 8SL, C=GB

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4125F00DB7D3D769AA161DDC92CC0CB3

File PE Metadata
Compilation timestamp:
2/6/2016 4:17:24 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:ifRtzHKXZYfL9QzxC54wrqgzP/nMV5EIPshpBG+Sc+AV+Z4wQfwEGuddhuCSdgV7:GRJKGktVYo5AVwQj/5G4OQb

Entry address:
0x103810

Entry point:
55, 8B, EC, 83, C4, F0, B8, B8, 32, 50, 00, E8, 08, 36, F0, FF, A1, 80, 85, 50, 00, 8B, 00, E8, 54, 5F, F5, FF, A1, 80, 85, 50, 00, 8B, 00, 33, D2, E8, 6A, 5B, F5, FF, 8B, 0D, 08, 80, 50, 00, A1, 80, 85, 50, 00, 8B, 00, 8B, 15, F4, C1, 4F, 00, E8, 46, 5F, F5, FF, 8B, 0D, B8, 84, 50, 00, A1, 80, 85, 50, 00, 8B, 00, 8B, 15, 78, BE, 4F, 00, E8, 2E, 5F, F5, FF, A1, 80, 85, 50, 00, 8B, 00, E8, A2, 5F, F5, FF, E9, BC, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1 MB (1,059,328 bytes)

The file 3d_instruktor_novoe_leto_2015.exe-torrent.exe has been seen being distributed by the following URL.