40 gradusov.exe

Mobilnye Proekty , Ooo

The application 40 gradusov.exe by Mobilnye Proekty , Ooo has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from forces.kubaniniman.ru.
Publisher:
Mobilnye Proekty , Ooo  (signed and verified)

MD5:
d31f06b8df8ad8323447c0019082d9df

SHA-1:
7a318f4b6da32e42ddf38eaa523d1a4c6e853b6c

SHA-256:
75d8d59b3d2f6e1c80e990716c98584a21ce1a5e7c96d68e8a540d3e8fe6dee6

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/27/2024 11:14:41 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.7.22

File size:
481.9 KB (493,464 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\40 gradusov.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/21/2014 4:00:00 AM

Valid to:
5/22/2015 3:59:59 AM

Subject:
CN="Mobilnye Proekty , Ooo", O="Mobilnye Proekty , Ooo", STREET="Tymenskaya 5, bld. 1", L=Moscow, S=Moscow region, PostalCode=107370, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D812EDF6481CAD30D5A8D2B9E47437D4

File PE Metadata
Compilation timestamp:
5/31/2014 12:05:44 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
27.26

Entry address:
0x997C

Entry point:
2B, 1D, 8E, E8, 40, 00, BD, D9, ED, 0E, 8B, 1D, 86, 70, 3B, 82, 19, D2, F5, 81, E5, 54, FB, 94, 0A, 90, 33, 2D, 66, 96, 44, 00, C1, E5, 16, D1, F9, 23, 6C, 24, FC, 13, 2C, 24, 45, 39, D4, 1B, 6C, 24, 14, C1, D5, 1E, 93, 8B, 4C, 24, 10, C1, C3, 14, C1, C7, 0C, F7, 44, 24, F4, 4E, 84, 76, 26, C1, E2, 17, F7, D1, C1, E2, 18, C1, E6, 0C, C1, FA, 1F, C1, FE, 17, C1, D1, 19, 43, 19, F7, C1, DB, 06, 1B, 54, 24, F8, 85, DA, 13, 35, 07, 4C, 40, 00, F7, D5, F5, 11, FD, FD, C1, C3, 19, 90, 81, CA, A6, C4, 6E, B0, F7...
 
[+]

Code size:
398.5 KB (408,064 bytes)

The file 40 gradusov.exe has been seen being distributed by the following URL.

http://forces.kubaniniman.ru/NTM2NTtodHRwJTNBJTJGJTJGenZ1a29mZi5ydSUyRmRvd25sb2FkJTJGMTU2MDIxNTtuYW1lPTQwKyVEMCU5MyVEMSU4MCVEMCVCMCVEMCVCNCVEMSU4MyVEMSU4MSVEMCVCRSVEMCVCMjtzaXplPTQyNTUxNTE7dHlwZT1hdWRpbw==

Remove 40 gradusov.exe - Powered by Reason Core Security