far_cry_2-4632.torrent.exe

Astonsoft DeepBurner

MALITEK

The application far_cry_2-4632.torrent.exe by MALITEK has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from s04d.storage.yandex.net.
Publisher:
Astonsoft  (signed by MALITEK)

Product:
Astonsoft DeepBurner

Version:
1.9.0.228

MD5:
d29199b381e1c5d8d6afe2e8eba7be82

SHA-1:
abcd75f4398f14e33b4260bf7af149a8da83dbee

SHA-256:
3de66fce47494557c02045d04960b33501c5944756ca18b35aa821027471716d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 7:02:55 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallMonster (M)
17.3.11.10

File size:
3.4 MB (3,585,992 bytes)

Product version:
1.8

Copyright:
Astonsoft (c) 2002 - 2006

Original file name:
DeepBurner.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\far_cry_2-4632.torrent.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/26/2016 4:00:00 AM

Valid to:
3/13/2017 2:59:59 AM

Subject:
CN=MALITEK, O=MALITEK, STREET="Gazovikov, 30, 160", L=Tyumen, S=RU, PostalCode=625022, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A01AEAF9B16F1620ED4B82F942BD3FDC

File PE Metadata
Compilation timestamp:
7/6/2009 4:15:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x7505D4

Entry point:
54, 6A, 1D, B9, 55, FC, 2F, 02, 33, C0, 03, 44, 24, FC, 49, 75, F9, FF, 15, B0, E3, B4, 00, BA, 40, 10, B5, 00, 42, FF, E2, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, BF, FD, 03, B5, 00, 81, C7, 12, 0C, 00, 00, 57, C3, EB, F1, 6A, 00, 58, 83, C0, 01, 33, DB, 8B, 88, 93, E1, B4, 00, 0F, B6, 09, 80, E9, B1, 83, E9, 07, 3B, CB, 75, 20, FF, 15, B4, E3, B4, 00, E8, F5, FF, FF, FF, FF, E9, A9, 09, E4, E9, A9, 09, E4, E9, A9, 50, 57, 6A, 01, 8B, FF, EB, B8, 09, E4, E9, A0, 08, 00, 00, CA, 9A, 64, 89, 22...
 
[+]

Code size:
650.5 KB (666,112 bytes)

The file far_cry_2-4632.torrent.exe has been seen being distributed by the following URL.

https://s04d.storage.yandex.net/rdisk/4c7c07f7a1513c119ea2b6da5048318a6a3c1778ba2e896e870c05fd9bf3ebf0/582dc9e7/75gHDkkGiP7JzxcXvqo1MePyvHyWasZaA5VT6tve5EpZj4W9jOuppc8mNF9CVLaMrxJkQ6mVaiGrSWMRo2C4tw==?uid=312266688&filename=Far_Cry_2-4632.torrent.exe&disposition=attachment&hash=&limit=0&content_type=application/x-msdownload&fsize=3585992&hid=76ca7bc28501efb99c4b5dd0e4c44a12&media_type=executable&tknv=v2&etag=d29199b381e1c5d8d6afe2e8eba7be82&rtoken=wAMdPfJK1uUi&force_default=yes&ycrid=na-85ada139fa1a2a6c1cff14d79713b057-downloader3h&ts=54180ae0907c0&s=6d4b5e2d7bddd5d32478f65ff1bb6344d846811b399e866b6815b061fd45e723&bp=/36/.../data-0.15:3680393188:3585992&pb=U2FsdGVkX18R9KqYrrLYf1rQl0QOY0aMdJFtiLDJCg5UuAwCxYrBurTQ--roS5pnn7AOEDmFGiXnO-g3AvECj2GqFfwa4caOzLOoWVdUO9A=

Remove far_cry_2-4632.torrent.exe - Powered by Reason Core Security