a3a8339d7d123ba817cc83e4d655ddbc_node-kit-pft.exe

Proxomitron

SBIS

The application a3a8339d7d123ba817cc83e4d655ddbc_node-kit-pft.exe by SBIS has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Groom-A-Zebu (tm)   (signed by SBIS)

Product:
Proxomitron

Description:
The Proxomitron

Version:
4, 5, 0, 4

MD5:
3df261abe16a3ab2d359cebf73538044

SHA-1:
8de9c48cd146a963748ceb5172cf65de7bcd186f

SHA-256:
ba767425e5af117c9aba86c81bf8c4aaf3a1452ffaec59d7f1d3e6f757de0712

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 7:55:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.15.5

File size:
600.4 KB (614,840 bytes)

Product version:
Naoko-4.5 2003-6-1

Copyright:
Copyright © 1999 - 2003 By Scott R. Lemmon

Trademarks:
Proxomitron, The, and the letters A-Z

Original file name:
Proxomitron.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\installmoney\a3a8339d7d123ba817cc83e4d655ddbc_node-kit-pft.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/2/2015 12:00:00 PM

Valid to:
5/2/2016 11:59:59 AM

Subject:
CN=SBIS, O=SBIS, STREET="PR-T MOSKOVSKIJ, 12", L=YAROSLAVL, S=YAROSLAVL REGION, PostalCode=150001, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009CA0BE54A9516364680AD45D6408C6A2

File PE Metadata
Compilation timestamp:
6/19/1992 10:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x7B9FC

Entry point:
E8, BF, 1A, 00, 00, 9C, C7, 44, 24, 04, FE, BD, 8D, B7, 8D, 64, 24, 04, 0F, 85, 7E, FD, FF, FF, 9C, 68, 78, 52, 15, 5F, C7, 44, 24, 04, 18, F3, 97, 30, C6, 04, 24, 15, 8D, 64, 24, 04, E9, 90, B9, 00, 00, E8, 20, 1E, 00, 00, 00, 00, 47, 65, 74, 4B, 65, 79, 62, 6F, 61, 72, 64, 4C, 61, 79, 6F, 75, 74, 00, 98, CF, 20, 0C, 4E, 6B, 3B, 20, 90, E5, 3B, 8C, E2, 37, 38, 79, D1, D8, 2E, 97, EF, 0A, 0B, 7C, 09, 5C, 6D, CD, 3C, 20, 4B, 9C, 84, 1F, 2C, E8, 59, 46, 5D, AA, 45, 96, 7D, B1, 94, C4, 5A, E7, 64, 4C, 3D, 40...
 
[+]

Code size:
441.5 KB (452,096 bytes)