araz dare - gomshodeh.mp3.exe

VKontakte DJ

RECORD LLC

The application araz dare - gomshodeh.mp3.exe by RECORD has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from musicloader.fr.
Publisher:
RECORD LLC  (signed and verified)

Product:
VKontakte DJ

Description:
VKDJ, Setup

Version:
1.4.48.0

MD5:
877bea2a9b5050a88c15776e7211f996

SHA-1:
e74ccf71b28f730beae5038e579ec8de7cd39632

SHA-256:
356435206cdd8a70085e9f85371e7725a80d9bab9f0072f7d333dfd581782249

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 10:50:05 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.14.7

File size:
6.5 MB (6,810,296 bytes)

Product version:
1.4

Copyright:
Copyright (C) 2008. All rights reserved.

Original file name:
VKontakte-DJ.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\araz dare - gomshodeh.mp3.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/5/2016 4:30:00 AM

Valid to:
2/17/2018 3:29:59 AM

Subject:
CN=RECORD LLC, O=RECORD LLC, STREET="Kolomyazhsky 33, liter A", L=Saint-Petersburg, S=Saint-Petersburg, PostalCode=197341, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
21C2EBF24FBBC6959C39DAD0D156CD23

File PE Metadata
Compilation timestamp:
6/20/1992 2:52:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xC8288

Entry point:
55, 8B, EC, 83, C4, F0, B8, F8, 7D, 4C, 00, E8, 2C, E9, F3, FF, A1, 9C, C2, 4C, 00, 8B, 00, E8, 74, 6E, FA, FF, 8B, 0D, B0, BE, 4C, 00, A1, 9C, C2, 4C, 00, 8B, 00, 8B, 15, 04, 3B, 4C, 00, E8, 7C, 6E, FA, FF, A1, 9C, C2, 4C, 00, 8B, 00, E8, 04, 6F, FA, FF, E8, F3, C1, F3, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8277

Developed / compiled with:
Microsoft Visual C++

Code size:
797 KB (816,128 bytes)

The file araz dare - gomshodeh.mp3.exe has been seen being distributed by the following URL.

http://musicloader.fr/.../ZWMwMDAxMDBiNDAwMDY0NjAwMDAwNjMzMDAwNjMzMDAwNjMzMjlmYWI3ZDVjZQ==?name=Araz Dare - Gomshodeh.mp3

Remove araz dare - gomshodeh.mp3.exe - Powered by Reason Core Security