download template.exe

TehnoSoft

The application download template.exe by TehnoSoft has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from disk-space.ru.
Publisher:
TehnoSoft  (signed and verified)

MD5:
4b90e38d2ee9df79cd2e5c830ffd32b4

SHA-1:
c204fbf506a126ae56c125c74b06e9021567ef26

SHA-256:
c206fd8af059c714e7b4e95e50d9845eb1a31300a5a46f9dc2883b77c2d3fa0d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/15/2025 4:34:35 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ICLoader (M)
17.2.19.10

File size:
536.5 KB (549,376 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\download template.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/9/2016 4:00:00 PM

Valid to:
3/10/2017 3:59:59 PM

Subject:
CN=TehnoSoft, O=TehnoSoft, STREET="LESNORYADSKY, 10", L=Moscow, S=Moscow, PostalCode=107140, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E310581086B798DAA679CA36054C27AB

File PE Metadata
Compilation timestamp:
4/2/2016 7:17:54 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x6BAF0

Entry point:
55, 8B, EC, 81, EC, 28, 09, 00, 00, 53, 57, C6, 85, 84, FE, FF, FF, 8F, 68, 88, 15, 00, 00, 6A, 00, FF, 15, C4, E5, 46, 00, 85, C0, 74, 02, CD, 52, 68, 68, C2, 47, 00, FF, 15, F0, E0, 46, 00, C7, 85, 0C, FE, FF, FF, 16, 00, 00, 00, FF, 15, 68, E7, 46, 00, 68, 80, C2, 47, 00, FF, 15, F0, E0, 46, 00, 8B, 85, 0C, FE, FF, FF, 83, C0, 0D, 89, 85, 0C, FE, FF, FF, 81, BD, 0C, FE, FF, FF, A3, 08, 00, 00, 72, D4, 68, 98, C2, 47, 00, FF, 15, 6C, E7, 46, 00, 8B, 0D, B4, C4, 47, 00, 51, FF, 15, 70, E7, 46, 00, FF, 15...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
434 KB (444,416 bytes)

The file download template.exe has been seen being distributed by the following URL.

http://disk-space.ru/.../getlink

Remove download template.exe - Powered by Reason Core Security