game37679-2267-torrent.exe

InstallShield

INTIS

The application game37679-2267-torrent.exe by INTIS has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the InstallShield Setup installer. The file has been seen being downloaded from s111f.storage.yandex.net.
Publisher:
Macrovision Corporation  (signed by INTIS)

Product:
InstallShield

Version:
12.0.49974

MD5:
0d3f4eb2446fefdd18215ba1bb3ba0de

SHA-1:
ba809495df1d2dade01bcfdfe7c7974b6bd08bd1

SHA-256:
2873fca72c828a8e20d04d490581b815e2d9277e8a225d918c4ea07ca1a7f191

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/30/2024 10:24:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.FileTour (M)
16.7.27.6

File size:
2.7 MB (2,779,592 bytes)

Product version:
12.0

Copyright:
Copyright (C) 2006 Macrovision Corporation

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Installer:
InstallShield Setup

Common path:
C:\users\{user}\downloads\game37679-2267-torrent.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/16/2016 4:00:00 AM

Valid to:
4/17/2017 3:59:59 AM

Subject:
CN=INTIS, O=INTIS, STREET="Prospekt 40-letija Pobedy, 69, 1, 8", L=Rostov-Na-Donu, S=RU, PostalCode=344072, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E0D42565A341BEBE1BAFBF6CA79F6420

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
49152:olKDltK9CqghBWGlbaWIl3ybzoCYs83WwtBsLl4DoHe4sB/DFvqX:aKvtqg78WIQIFLul4DOjsB/DFyX

Entry address:
0x76B13B

Entry point:
54, 6A, 40, 68, 00, A0, 00, 00, 68, 00, A0, B6, 00, 6A, FF, B8, 0E, 31, B5, 00, 40, 68, 57, B1, B6, 00, FF, 20, 0F, 84, A3, EE, FF, FF, 0F, 85, 9D, EE, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
2.5 MB (2,608,128 bytes)

The file game37679-2267-torrent.exe has been seen being distributed by the following URL.

Remove game37679-2267-torrent.exe - Powered by Reason Core Security