microsoft_toolkit_final_56voi.exe

Download Manager

REAL-TRAST LTD

The application microsoft_toolkit_final_56voi.exe, “Download Manager installer” by REAL-TRAST has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from 64174.get-wn.net.
Publisher:
Download LTD  (signed by REAL-TRAST LTD)

Product:
Download Manager

Description:
Download Manager installer

Version:
1.3.0.0

MD5:
b46d22b43b4450a49025647d9feb07b6

SHA-1:
c3c687be4fff9b34926f5880a980fce921899e35

SHA-256:
91000db85feb83e80f639020740b8c0686c116dc61e732b7aa08dd2908fd2727

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 12:32:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.REALTRAST.Installer (M)
16.2.20.4

File size:
2.3 MB (2,420,736 bytes)

Product version:
1.1.0.0

Copyright:
Copyright 2014, All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
Swedish (Sweden)

Common path:
C:\users\{user}\downloads\microsoft_toolkit_final_56voi.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/13/2014 2:00:00 AM

Valid to:
10/14/2015 1:59:59 AM

Subject:
CN=REAL-TRAST LTD, O=REAL-TRAST LTD, STREET="ulitsa Mira, 42", L=Zelenogorsk, S=Kray Krasnoyarskiy, PostalCode=663690, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1518FDB896310E434A331B0D8150656D

File PE Metadata
Compilation timestamp:
11/21/2014 6:22:37 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:VrPzxvEPAcKMdO0uZJBwT4timKIT2KhoKWUDnuqxN/k6i:ZPzx0AWO0iJ+ToDnh1zn5kp

Entry address:
0x1F5DD

Entry point:
55, 89, E5, 83, EC, 6C, 68, 43, 45, 41, 00, E8, 80, A6, FF, FF, 8B, 55, 14, 89, 78, 24, 8B, 7D, 0C, 57, FF, 15, 50, 41, 44, 00, 85, C0, 75, 12, 8B, 5D, FC, 8D, 46, FF, 85, F6, 0F, 8C, F5, FF, FF, FF, 7F, 2B, 74, EE, 81, FF, 37, 01, 00, 00, 75, E6, 8B, 4E, 04, 3B, C1, 0F, 85, E1, FF, FF, FF, FF, 75, F0, 53, C1, E6, 04, 89, 75, E0, 3B, 35, F8, 60, 44, 00, 0F, 8D, ED, FF, FF, FF, C6, 84, 24, C0, 00, 00, 00, 01, 8D, 4C, 24, 50, E8, EE, A2, FE, FF, 8B, 4E, 3C, 8D, 45, 08, A3, B4, 63, 44, 00, 8B, 85, E0, FC, FF...
 
[+]

Code size:
268 KB (274,432 bytes)

The file microsoft_toolkit_final_56voi.exe has been seen being distributed by the following URL.

Remove microsoft_toolkit_final_56voi.exe - Powered by Reason Core Security