microsoft_visual_c_2005-2008-2010-2012-2013-2015_redistributable_package_hybrid_2015_pc_downloader.e

Zurumbia

Cool Idea Inc. LTD

The file microsoft_visual_c_2005-2008-2010-2012-2013-2015_redistributable_package_hybrid_2015_pc_downloader.e by Cool Idea has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from p-def6.pcloud.com.
Publisher:
Zurumbia Incorpatated  (signed by Cool Idea Inc. LTD)

Product:
Zurumbia

Version:
1, 0, 1122, 1

MD5:
df1ef18acdd3fdf94554f540ce7a6a6d

SHA-1:
05ccda4dbe489053942489027a3de7b98ea4a6ad

SHA-256:
7471307439267454f8537afbe48ddab15bbf8beb69867a177dc533a37e2eaac0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 5:45:28 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ExpressFiles (M)
16.7.25.18

File size:
3.7 MB (3,910,392 bytes)

Product version:
4.0.0.1

Copyright:
Copyright Zurumbia (C) 2016

Original file name:
Zurumbia.exe

Language:
English

Common path:
C:\users\{user}\downloads\microsoft_visual_c_2005-2008-2010-2012-2013-2015_redistributable_package_hybrid_2015_pc_downloader.exe

Digital Signature
Authority:
Cool Idea Inc. LTD

Valid from:
4/8/2016 8:27:58 PM

Valid to:
4/8/2017 8:27:58 PM

Subject:
CN=Cool Idea LTD, OU=Cool Idea LTD, O=Cool Idea Inc. LTD, S=Southampton, C=UK

Issuer:
CN=Cool Idea LTD, C=UK, S=Southampton, L=Southampton, E=admin@coolidea.com, OU=Cool Idea LTD, O=Cool Idea Inc. LTD

Serial number:
100001

File PE Metadata
Compilation timestamp:
4/6/2016 10:43:03 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
98304:rFmiyI8zYfOrwJHlqini6CqGQjxEKn2UVnDaa1LI0:3Fk36zEK2UVDaa1LI0

Entry address:
0xC609E

Entry point:
E8, 38, 0C, 00, 00, E9, 80, FE, FF, FF, 55, 8B, EC, FF, 75, 08, E8, 59, FC, FF, FF, 59, 5D, C3, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, F2, C3, 8B, 4D, F0, 33, CD, F2, E8, 02, F5, FF, FF, F2, E9, DA, FF, FF, FF, 8B, 4D, EC, 33, CD, F2, E8, F1, F4, FF, FF, F2, E9, C9, FF, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 34, 60, 57, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00...
 
[+]

Entropy:
7.6675

Code size:
1.2 MB (1,247,232 bytes)

The file microsoft_visual_c_2005-2008-2010-2012-2013-2015_redistributable_package_hybrid_2015_pc_downloader.e has been seen being distributed by the following URL.