alrdofpe.exe

Bordurers

Itgms Ltd

The file alrdofpe.exe by Itgms has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from paiyafototips.com and multiple other hosts.
Publisher:
Avor regata   (signed by Itgms Ltd)

Product:
Bordurers

Description:
Karat

Version:
1.00

MD5:
a47420dc53bfe082854881c207e712c1

SHA-1:
90460e13a54b759c246d3c45824c700b29aa3551

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 12:30:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Downloader (M)
16.4.28.14

File size:
357.3 KB (365,856 bytes)

Product version:
1.00

Original file name:
Kalkerings8.exe

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\alrdofpe.exe.part

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/17/2015 5:00:00 PM

Valid to:
11/17/2016 4:59:59 PM

Subject:
CN=Itgms Ltd, O=Itgms Ltd, POBox=LS15 8JJ, STREET=44 Sandbed Court, L=Leeds, S=West Yorkshire, PostalCode=LS15 8JJ, C=GB

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
642AD8E5EF8B3AC767F0D5C1A999BDAA

The file alrdofpe.exe has been seen being distributed by the following 5 URLs.

https://paiyafototips.com/6671658224582/6671658224582/.../FlashPlayer.exe

https://paiyafototips.com/4491219442287/4491219442287/.../FlashPlayer.exe

Remove alrdofpe.exe - Powered by Reason Core Security