lego-worlds-846-torrent.exe

Carwambis Installer

INTIS

The application lego-worlds-846-torrent.exe, “Express Installer” by INTIS has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from downloader.disk.yandex.ru.
Publisher:
Carwdambis (wdMEDIAd FOG LTD.)  (signed by INTIS)

Product:
Carwambis Installer

Description:
Express Installer

Version:
1.0.0.2

MD5:
7c37a03623dfe2137f85692a72ee55b3

SHA-1:
107c4940427fc6e988fb8bf42bf5cd5738258f7f

SHA-256:
c06b16c083363ce55b648c3143b6202c1b54dce5387d8fb514a7c1a439f7127b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 1:47:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.FileTour (M)
17.3.2.13

File size:
2.2 MB (2,271,688 bytes)

Product version:
1.0.0.2

Copyright:
Carwdambis (MEDIA FOG LTDdw.) All rights reserved. 2014

Original file name:
dw

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\lego-worlds-846-torrent.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/16/2016 6:00:00 AM

Valid to:
4/17/2017 5:59:59 AM

Subject:
CN=INTIS, O=INTIS, STREET="Prospekt 40-letija Pobedy, 69, 1, 8", L=Rostov-Na-Donu, S=RU, PostalCode=344072, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E0D42565A341BEBE1BAFBF6CA79F6420

File PE Metadata
Compilation timestamp:
10/8/2015 11:44:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

Entry address:
0x386008

Entry point:
53, EB, 0E, 50, EB, 0B, 52, EB, 08, 56, EB, 05, 55, EB, 02, 33, C0, B9, 55, 2C, 01, 00, 51, 58, 49, 75, FB, E9, B2, 08, 00, 00, BE, C8, EE, 81, EA, CD, D8, 11, 00, 68, 1E, 6E, 78, 00, C3, 94, 05, C4, CF, FE, 00, 68, 9A, 64, 78, 00, 9C, FF, 44, 24, 04, 9D, C3, 67, 29, 64, 89, 21, E9, 2B, 12, 00, 00, DD, 8B, C3, E9, 2B, 10, 00, 00, EC, E9, 58, 0A, 00, 00, 3E, BA, 9E, 15, F5, 00, E9, 8E, 13, 00, 00, 1A, A4, BF, B8, FC, 93, 00, E9, 17, 01, 00, 00, 6F, B3, A5, 56, E9, 35, 07, 00, 00, B0, C3, E9, F9, 14, 00, 00...
 
[+]

Code size:
2 MB (2,094,080 bytes)

The file lego-worlds-846-torrent.exe has been seen being distributed by the following URL.

https://downloader.disk.yandex.ru/disk/e13f271076e84e2f2fbe15d304a91ea54acebcb25aec41320eecd7205611b8c1/575f017c/.../x-msdownload&fsize=2271688&hid=7fcb62255b9ff74cf00ea4ca7259935a&media_type=executable&tknv=v2&etag=7c37a03623dfe2137f85692a72ee55b3

Remove lego-worlds-846-torrent.exe - Powered by Reason Core Security