{blocked}.exe

Zona installer

Chetvertoe pokolenie, OOO

The application {blocked}.exe by Chetvertoe pokolenie, OOO has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from www.binariesbestgift.com and multiple other hosts.
Publisher:
4th generation  (signed by Chetvertoe pokolenie, OOO)

Product:
Zona installer

Version:
1.0.7.3

MD5:
92f2bddb06090cf5333f1c7c6f5a2d46

SHA-1:
fb5ecd01217e75f5e0c222e64890310e95fb9e4c

SHA-256:
d67c9ade0a1f2de77a29606d9c027c5d441b7b07a0db901066efd9eb563af40b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 1:55:56 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Zona.Chetvert.Installer.Meta (M)
16.5.25.16

File size:
810.7 KB (830,136 bytes)

Product version:
1.0.7.3

Copyright:
Copyright (C) 2015

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\rapala_pro_bass_fishing_en_simulation_2010_psp[pnrd].exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/28/2015 5:00:00 AM

Valid to:
8/28/2016 4:59:59 AM

Subject:
CN="Chetvertoe pokolenie, OOO", OU=IT, O="Chetvertoe pokolenie, OOO", STREET=d.41-A prospekt Lenina, L=Chelyabinsk, S=Chelyabinsk, PostalCode=454091, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
147448E7A60124EF7677AAD6BDC1E889

File PE Metadata
Compilation timestamp:
5/24/2016 1:04:44 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:gDOuf2/Zb2/nwSmBttiuQLDcjw3sn5IqMowLIuJfNIHCj3JdXxDqtBsGmk0X/4UB:gaur/Uye4FI+dhDRGmk0XAUARGUdPI

Entry address:
0x52E54

Entry point:
E8, 36, 4B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8D, 45, 18, 50, 6A, 00, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 4B, 26, 00, 00, 83, C4, 18, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 45, 14, 56, 85, C0, 74, 41, 83, 7D, 08, 00, 75, 13, E8, 67, 1B, 00, 00, 6A, 16, 5E, 89, 30, E8, B4, 3C, 00, 00, 8B, C6, EB, 2A, 83, 7D, 10, 00, 74, E7, 39, 45, 0C, 73, 0E, E8, 49, 1B, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, DE, 50, FF, 75, 10, FF, 75, 08, E8, 06, FA, FF, FF, 83, C4, 0C, 33, C0, 5E, 5D, C3, 8B, FF...
 
[+]

Code size:
466 KB (477,184 bytes)

The file {blocked}.exe has been seen being distributed by the following 43 URLs.

http://www.binariesbestgift.com/9PjeTNV sYlFB4PXoB8e32c1wQjLDk3bltVBLnTU3oABd0YJtdCAwX5bK8asA8uIBvTVw2_r3mDGcNQcizqFY8Lyzm5CkeQSElrLlmgTnZmxVRVoTLj9 LK39TiVFEiCu45_W36pM0Bhy_q dc_e3_XqJtDUVPK4Rt3p4X0XHpwQVgR119Q=-GzQAAOTwGtKCTmxA2V_Zg4gii0aK yznuZZIGNiua1pc5_8cJNt9qjM6l3XRgCnwzhJIHN8I

http://www.binariesbestgift.com/HAJvEgvW_24oEMvr6snZcceijLN5pOMHdMhHkM9bYXDU0QmIxmDHrxYHIOEozbKeq1s_OVekVP_BRaGdkNo6I9Lox0l HvRaDWCaTvzcxnkOP88RXztJYCIf7Wf9DH25aQZM NnxjbaYOiwrb0LsaOLP0VJ9xqEXGmZSDxJMC2SjUfRwMYz1AD_ VFt67FrF5mQRUa0u-G1AAAMTc2vOnn6_8_UWMkYNJNo5aloMNOHCILMABdJtvi_tOqjuSiDYSA9Hitcb35HN0LAoeDx49VMyWkDH5pOsNQrY2n3fHVip8T_IL

http://www.binariesbestgift.com/NlBBxwD3GUUq_Z9YW1onC4rMmgno36Uhn6dD4ZVAOqbrS9UZNHFAAxzpF6WpE702hc4ORbfgb4FhAN2qaOWMylnifzftZJJwln6GbgLqRk0ai51nmy17_QLGWp1dM8_MjBJBK8__fFfxlwX3rofpVyVC7Gko8vbW1K7cm6EiVSOsmeTL6_WuIEILhe82seDTKUYOMG1oWHm FzVxFkzqidvZfTA0 w==-G1wAAMSgeTGNobItFN1LE2EiBw6RBXggbHt 3Ko5z5XEiBDTdUVL1 N_juSI19jTfV1uRLDzYP2jOHYpZmtwS7_cuJHjPGMQDFiFwn4dXdMWGGL5Sg==

http://www.binariesbestgift.com/16a5j0s4z5QL6a8yf8GfVkuntsEw4mjWLfWJRx0__Vps3zxpWPfpHmk0pkMQYxFdp7onftSR9JFVJUuO7Lz JfaSUyErBVhVFOifNH6cuNIe wv8MPK5RhTh43T6dZUXfSctH4nfP8zd3I4z6taKXZHxHxXBqmwdPE5UQsgimECfkGrbhtyR2RbwOvkVpx5eSuCMDSu2TIi1nZEHz 1dxflO5EZ0kPxE32oJntewt22B6ZNkxYM=-G3UAAETBbbGdUghdbFdD1A0OHAIMLMCiADScho0xx24HTmXPsyphMhJWq7T49fE_R3PuDkmdO0NmEtde7qwSaM7wMZyKr7BF2AvZDwsKossBqXA6ODwsn_jKBTMnrNxdndoOYSHqVQ==

temp:grudastaya_indiyskaya_devushka l_kR .exe

http://www.binariesbestgift.com/QrMJ8y6RhLxbj3m7zphiCIs02tHHpDkUzbey4TTGZuTP0HrGjNmat1rksE4VDJTsXlvAfmURbChtav_xm OFRd1DnbyoMow4q7IQAGo4XToklR6lSpQCfhB _IvmZjxEQH8LC OnTce0ksTLf5cL1Afan9gWRY7XCT9pZLnFRcjLVd9y2A5UQ KLgeCdaZp869SpiE_U257D5DdWtcZw3fHnzslHWw==-G18AAORNd16z54qeI0KshEmisgll4JATDgxbZAcMQCMLNsZAPDOSnhlJ1K1AEdFmV_53Ls9cgm5KZdgQKzG PUNmoUclXl2y8OQZSmkOg8a rRUH8Mc=

http://www.binariesbestgift.com/iSiJcRTJXv95IRuoMVKHlH4McyWpZnJZ9fjCIrBk9vWazmfhiYmCVGnEIpm8VmsmprC5uCyC69apIMxvVZu9nhwxAemxI dqAc14_jrhL6H3fh0Z3S40seDswxxf VsXj4Gcl0dwi5xJUvog4uzxwt4atKdV28CQZ 86IIRcpWCm2iSQyHg=-Gz0AAGR3nt kPK_jktZCUWTZBD2IKLIIJD9OsqoyieQOxIyWr_ePmPFQ2pDo7qRzIbRHTsF5uyKUWwA=

http://www.binariesbestgift.com/hMOfTlypvnqkG0PM3DbxwCKAqEKqHpfnvqXCLVcck6E3BwdEmB0O3C7FlABz_xcXJf90da9Ka nth6o4nsbixHtqEt_WcVAEAK7o8ZxwNesGW7u0YjR0R8N4uC3D3VqLQ4b1UQsCcBk8whJLBnmPhPgUZhHkVACr1AzJZ5y5j6SJLZNRhc0=-GzQAAGR3nt W03O6pUVWRFqZBtiAA4fIAgwA5_PjMJuqkEidkEXQ8vV823hW10fGheIjuhF8Ar4M

http://www.bodyapplicationsafe.com/c?x=sRS4 s0 gHUxmUZp1CZ82HfvSUao RcyRC8ARMbAHXY=&c=4yV 4HMfMVqLWT9V29eCoTriNtio/DHmtuEkvF3yl6fMdm2RNbHGsxDNRGasktBna1c3FMuYLFpy/.../GOkHTkOMFgmV8WnzUIZcMYmG

http://www.binariesbestgift.com/g5T534EjFTSzK5Nsnf4H1aWv4D2kTiJrr40BnzQ6Szq1m6cHiDKTW8xk9242IcgxiBAsyJh7nZeIFWQPyz1fyRTlklSnHIyu8YmPqSk28WOJCQJogwIJntnIG_y4uu2I7rKv9ZWvyD2e4YiHW6Crejkz67mvsdNgEKjLJA31mZfFlS2qpxA=-CxuAaHR0cHM6Ly9kbC5hcHB6b25hLm9yZy96d3MvcmVzaGlsYV9wb3Byb2JvdmF0W3FKeXldLmV4ZQM=

http://www.binariesbestgift.com/c6pdt5lNe3vqNh21XlIKIdwLWdUmTMB493mBAIstlr6Ti99yiMtNilAwNpztp5 o56kxaIAWmd6wC2wRaHtcP6j3_YjOXVNo BXp6LFLdn6HY3cKKhSmwH6kBBE5smv97PLQ2qDIoq0X eZqhABvKsqvF5bZiKfq0nZ6nGn3Dbu9 DUHaFEmkVJzsqcdd3KYTABuQ7PD20VcIAlkjcBpniMxHoJr Q==-G28AAMTIbbGNROgcodpPHdwNDhwiC8MMwwjbh4kcJPqVn_Y8axImI2G1Rotdz_85hsNFlU9YLyNG8HB2nlGhaJxWQZWCfuFdgNhZOsLcqGKZQpk3ol4F

http://www.binariesbestgift.com/15pxJmVDvFt9FUtc9di13vo5rMrtxO4tvgWKVWJN0UOkG5PrMa5K4ptZ7UOZogEyUQFtXdf9n3EfkOrqkEhQ_m9QC5uEtXs1YtOLUdf_4f8DIX9FztF4 pAOKUzlXMBta_tLwQ3cd8gCs9QRc_g5Xg6vjJwvPz0CkV7xN oPxjg_nsRZ2_BpG_fAyeKi3BkeXIy4LFxsbkgMtdLBpLhq_l9pM1hSvQ==-G3gAAMSgebE9nOJ8A wGB xlrcP8YOtoCwYesinFBPOo2_NckVjlSLJ1hZa9zv8cdG1YVuBUIDBmcXNFGFHWSALsxdm12ZfhOmR8yz1k8NTrjNKoAL9fR8h578Wkeis=

http://www.binariesbestgift.com/be1jLxFbD2XG3wi69BctIc_it 8r3KQ FqW18NRMB Jx4ApRdz1JYCuYdJipf5K7Fke8_XJkmZyt_OQWtUBw0pqm3NgMpuN8u5cUH xnRuXAQ_u2U5CWCDr7rO91EKm_e0xcyGAHVGc9Hb8KYLWo_OTO1d rx_9KQVb9UoIbvqT3QvDnhPOAaz3OyvVZDr8nFbFJZ4am-G0EAAMTaOW5flME0GaTvgwyGw4vABpxoYL4tOOAAul3cl66KElUGCZBWrvy75wEkL2nKYG7zssuGLLnoMUOi io=

http://www.binariesbestgift.com/yCg8ZuF80Q bNv_9DHr_C 2cF0rc clnnEagMXN3Vvd61KkKJmcXv8K9HAXltXiwtq9p4exBUMnwIF2jp9 _Yumr1JmwVp0bDuac0OKJ3op0ml_fPI6MRdV_EBdxIq6av6i9BOaHQh5QVAv XL4OFV8WsGrvcdIy0QSkT 9ZhoU2t64u520=-GzsAAORt4vnZVcfd8UeIkDQhSaEINuDAIbIAA9DBzo zbGZCImUBiaDl6_hXXTVCj9l59uoTlex0SXEEzcCPAQ==

Latest 30 of 43 download URLs

Remove {blocked}.exe - Powered by Reason Core Security