brastub6ab_amobl_inst.exe

The application brastub6ab_amobl_inst.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from d3r8ssqwsd059p.cloudfront.net and multiple other hosts.
Version:
1.0.2.1

MD5:
9af6a67e4b0c7410bc3fd12884159158

SHA-1:
3495613cbdd40fa79140426ec4ccfd885e09e644

SHA-256:
8a0b62bafb9bcc021572b0deb1c90689cc1fc583064438b7c4f14ca9f1448f08

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/26/2024 9:45:21 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Downloader.Meta (M)
16.7.14.15

File size:
414 KB (423,936 bytes)

Product version:
1.0.2.1

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\brastub6ab_amobl_inst.exe

File PE Metadata
Compilation timestamp:
7/14/2016 11:51:45 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
14.0

CTPH (ssdeep):
6144:XOX3r2Q8ov3JzAofasuY87AXxaz0LKDlNVb/G8f5gQFA7tx:eX3riov3JzAoisM7AfwNVnf5atx

Entry address:
0x18E0

Entry point:
E8, 68, 9E, 03, 00, E9, 08, 98, 03, 00, 6A, 08, B8, 09, FE, 44, 00, E8, AE, B9, 04, 00, 8B, F1, 89, 75, EC, 83, 65, F0, 00, E8, 7B, 4B, 00, 00, 83, 65, FC, 00, C7, 45, F0, 01, 00, 00, 00, 8B, C6, E8, 68, B9, 04, 00, C3, 55, 8B, EC, 83, EC, 14, A1, 08, 50, 46, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 89, 55, EC, 57, 8B, F9, C7, 45, F0, 1E, 4D, 6A, 6C, B1, 1E, C7, 45, F4, 4D, 6A, 6C, 5F, 88, 5D, F8, 8B, C3, 30, 4C, 05, F1, 40, 83, F8, 07, 73, 05, 8A, 4D, F0, EB, F1, 8D, 45, F1, 88, 5D, F8, 50, FF, 35, 34, 03...
 
[+]

Code size:
333 KB (340,992 bytes)

The file brastub6ab_amobl_inst.exe has been seen being distributed by the following 2 URLs.

Remove brastub6ab_amobl_inst.exe - Powered by Reason Core Security