installerdu-2.4.1.3369.exe

Carambis Installer

ROSTPAY

The application installerdu-2.4.1.3369.exe by ROSTPAY has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.windowsdrivers.ru and multiple other hosts.
Publisher:
Carambis (MEDIA FOG LTD.)  (signed by ROSTPAY)

Product:
Carambis Installer

Version:
1.0.0.2

MD5:
e1cd522a0214a2834cf9d6ea12ad1b95

SHA-1:
c89d084703149e8122b905b02949b9b6a7783acc

SHA-256:
910a92216d82fe995c259967fff15ba909cc925cbb26dc24d83b7d6c4e7750bb

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 12:53:35 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:PUP-gen [PUP]
2014.9-150501

Dr.Web
Program.Unwanted.271
9.0.1.0121

herdProtect (fuzzy)
2015.7.31.4

Trend Micro House Call
Suspicious_GEN.F47V0302
7.2.121

File size:
919 KB (941,088 bytes)

Product version:
1.0.0.2

Copyright:
Carambis (MEDIA FOG LTD.) All rights reserved. 2014

Original file name:
Carambis Installer

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\installerdu-2.4.1.3369.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
12/17/2014 2:05:04 PM

Valid to:
12/16/2016 6:35:09 PM

Subject:
CN=ROSTPAY, O=ROSTPAY, L=Rostov-on-Don, C=RU

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
27ED6D593F8321

File PE Metadata
Compilation timestamp:
12/18/2014 11:22:46 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:ohwv6RjKJ7OYu7qgOgJ5yVihLKuovdmPrqiTGdaOcIZJ:+xKxgJEViRKd1yr5TKDc8

Entry address:
0x2BC2B0

Entry point:
60, BE, 00, C0, 5D, 00, 8D, BE, 00, 50, E2, FF, C7, 87, 34, 51, 27, 00, 41, 08, BE, BE, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, D8, A7, 2B, 00, 57, 83, C3, 04, 53, 68, AA, 02, 0E, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9...
 
[+]

Code size:
900 KB (921,600 bytes)

The file installerdu-2.4.1.3369.exe has been seen being distributed by the following 3 URLs.

Remove installerdu-2.4.1.3369.exe - Powered by Reason Core Security