dg6aq5bzir

armandlamoureuxtechnology.com

The file dg6aq5bzir by armandlamoureuxtechnology.com has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from www.pelletiertechnology.com.
Publisher:
armandlamoureuxtechnology.com  (signed and verified)

MD5:
cd521f332137d34d96bbaf9ca9bb7575

SHA-1:
5217bb96cbc65db9e77cf90ae3284875c9fb0c53

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 7:45:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.armandla (M)
16.3.27.21

File size:
4.3 MB (4,484,352 bytes)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ifsbgr7psb\dg6aq5bzir

Digital Signature
Authority:
thawte, Inc.

Valid from:
8/4/2015 7:00:00 PM

Valid to:
8/4/2016 6:59:59 PM

Subject:
CN=armandlamoureuxtechnology.com, O=armandlamoureuxtechnology.com, L=Montreal, S=Quebec, C=CA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
70A446973E180652B0BF113D611E2136

The file dg6aq5bzir has been seen being distributed by the following URL.

Remove dg6aq5bzir - Powered by Reason Core Security