chit-nevidimka.exe

IT Proekt Invest, TOV

The application chit-nevidimka.exe by IT Proekt Invest, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install. The file has been seen being downloaded from soft-archive-12.ru.
Publisher:
IT Proekt Invest, TOV  (signed and verified)

Version:
1.1.4.3

MD5:
dd8ac9f638d02bd9bc498a0fb39d08c1

SHA-1:
286d1e0db6f1d4a12bfa6adaf7ed75d2218adb29

SHA-256:
cea4d3623cf175a50097426b1f7995d2e7945794956d1fb6eb7793ae83469c09

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 2:58:49 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize.ITProekt (M)
16.4.24.13

File size:
6 MB (6,316,512 bytes)

Product version:
1.1.4.3

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\chit-nevidimka.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/20/2016 5:00:00 AM

Valid to:
3/18/2017 4:59:59 AM

Subject:
CN="IT Proekt Invest, TOV", OU=IT, O="IT Proekt Invest, TOV", STREET="prosp. Vozzyednannya, 9", L=Kiev, S=Kiev, PostalCode=02160, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BFE3D72E3FB3938D9D5EBA447C681BDA

File PE Metadata
Compilation timestamp:
1/19/2011 6:42:57 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
24576:HtcMBwUzmflNY+zrYJHtP5pTeVRrLqbT6Woq7emli3cezjNgylihY15MEi1L1KUy:Ht9mfNYJtuMT0R/T6Pl1KUMZYA

Entry address:
0x5443C0

Entry point:
55, 8B, EC, 81, EC, A0, 08, 00, 00, 0F, B6, 85, 58, FF, FF, FF, 3D, 7D, DC, 00, 00, 7E, 16, 0F, B7, 8D, 8C, FE, FF, FF, 0F, B6, 95, A9, FE, FF, FF, 3B, CA, 0F, 8E, 85, 01, 00, 00, 81, 7D, E0, 44, 74, 00, 00, 72, 21, 83, 7D, C4, 00, 77, 1B, 8B, 45, B8, 05, 9E, D4, 00, 00, 89, 45, 84, 33, C9, 2B, 4D, A4, 81, C1, EF, 11, 00, 00, 89, 4D, C0, EB, 27, BA, E1, 1F, 00, 00, 2B, 55, AC, 89, 95, 74, FF, FF, FF, 8B, 45, F4, 2D, B4, F6, 00, 00, 66, 89, 85, C0, FE, FF, FF, C7, 85, 5C, FF, FF, FF, 73, 76, 01, 00, 81, 7D...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
5.5 MB (5,765,632 bytes)

The file chit-nevidimka.exe has been seen being distributed by the following URL.

Remove chit-nevidimka.exe - Powered by Reason Core Security