62228__tv-torrent.org-id1-torrent.exe

Carwambis Installer

INTIS

The application 62228__tv-torrent.org-id1-torrent.exe, “Express Installer” by INTIS has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from 46.101.156.172.
Publisher:
Carwdambis (wdMEDIAd FOG LTD.)  (signed by INTIS)

Product:
Carwambis Installer

Description:
Express Installer

Version:
1.0.0.2

MD5:
24503f4fe772098332b8e7852537e6eb

SHA-1:
9ffd0ec30fc9f34e35da9b674ab5dc738c26bf4e

SHA-256:
e60519b9b1da8f73163f0ce553b9d781312654987980333aaeedf9667dbac098

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 11:23:22 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.FileTour (M)
17.3.5.6

File size:
2.1 MB (2,174,920 bytes)

Product version:
1.0.0.2

Copyright:
Carwdambis (MEDIA FOG LTDdw.) All rights reserved. 2014

Original file name:
dw

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\62228__tv-torrent.org-id1-torrent.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/16/2016 3:00:00 AM

Valid to:
4/17/2017 2:59:59 AM

Subject:
CN=INTIS, O=INTIS, STREET="Prospekt 40-letija Pobedy, 69, 1, 8", L=Rostov-Na-Donu, S=RU, PostalCode=344072, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E0D42565A341BEBE1BAFBF6CA79F6420

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

Entry address:
0x63F009

Entry point:
50, EB, 0B, 51, EB, 08, 52, EB, 05, 53, EB, 02, 33, C0, B9, 55, 24, 01, 00, 51, 58, 49, 75, FB, E9, 84, 07, 00, 00, DB, 43, 37, 8D, 64, 24, 04, E9, DC, 0C, 00, 00, F8, 58, B8, 3E, BE, 8F, 01, E9, F7, 03, 00, 00, 4B, 9F, 68, 9F, F2, A3, 00, C3, 0B, 67, E6, 8B, 54, 24, 0C, 68, 6C, 07, A4, 00, C3, 1B, B9, B5, 1B, 87, 01, E9, DC, 18, 00, 00, 29, 40, 3C, BA, D9, 70, 3F, 00, E9, 1E, 16, 00, 00, B6, 29, 05, 54, 2D, 1C, 00, 68, 34, 13, A4, 00, 9C, FF, 4C, 24, 04, 9D, C3, B2, 81, E9, 21, 12, F3, FF, 68, E7, 27, 22...
 
[+]

Code size:
2 MB (2,084,352 bytes)

The file 62228__tv-torrent.org-id1-torrent.exe has been seen being distributed by the following URL.

http://46.101.156.172/api/download/bPcARO8nyHQ/lydCquoNukSRRkvU9U8BCQ/lydCquoNukR2Nllgy1foXg/.../Tt2DRwr442LqmAPF5LqUra9HrhjaH2TzSffaGWRHaiSuSirVxmO97w

Remove 62228__tv-torrent.org-id1-torrent.exe - Powered by Reason Core Security