milky chance - stolen dance zaycev net.exe

Kripto

The executable milky chance - stolen dance zaycev net.exe has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from forces.spbloadfile.ru.
Publisher:
Kripto  (signed and verified)

MD5:
87a916d86eea750c1494986f54ceafa3

SHA-1:
f1bfe1da36ccdf4d0d2d82a890a15daadedbea7a

SHA-256:
bb0c384b7c3ae8da1c623e5d9f5c9e4e9caf01749a9594bc67ea82e3441b7614

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/5/2024 4:44:19 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.12.12.16

File size:
369.4 KB (378,232 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\milky chance - stolen dance zaycev net.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/13/2014 3:00:00 AM

Valid to:
3/14/2015 2:59:59 AM

Subject:
CN=Kripto, O=Kripto, STREET="10 str. 4, ul.Brestskaya 1-Ya", L=Moscow, S=Moscow region, PostalCode=125047, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
50151AAA785A5F33ED83B2C33268D51D

File PE Metadata
Compilation timestamp:
3/30/2014 1:13:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
41.22

Entry address:
0x647A

Entry point:
55, 8B, EC, 83, EC, 08, 8B, 45, FC, 83, C0, 01, 89, 45, FC, 8B, 0D, BC, B7, 45, 00, 03, 0D, B4, B7, 45, 00, 89, 0D, BC, B7, 45, 00, 8B, 15, C4, B7, 45, 00, 83, EA, 01, 89, 15, C4, B7, 45, 00, 81, 7D, F8, CE, 00, 00, 00, 0F, 8C, B8, 00, 00, 00, 8B, 45, FC, A3, D4, B7, 45, 00, 8B, 0D, C0, B8, 45, 00, 51, 8B, 15, 90, B8, 45, 00, 52, A1, C0, B8, 45, 00, 50, 8B, 0D, A4, B8, 45, 00, 51, 8B, 15, 90, B8, 45, 00, 52, A1, C0, B8, 45, 00, 50, FF, 15, 1C, A0, 45, 00, A3, 88, B8, 45, 00, 83, 3D, 88, B8, 45, 00, 00, 74...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
352.5 KB (360,960 bytes)

The file milky chance - stolen dance zaycev net.exe has been seen being distributed by the following URL.

http://forces.spbloadfile.ru/MjU1NTtodHRwJTNBJTJGJTJGZGwuemF5Y2V2Lm5ldCUyRjU1MmM2NjU5LWNjNjMtNDY0Yi05YjYyLTQ3MzA1N2NkNTM5OCUyRjE5OTkxJTJGMTk5OTE0MyUyRm1pbGt5X2NoYW5jZV8tX3N0b2xlbl9kYW5jZV8lMjh6YXljZXYubmV0JTI5Lm1wMztuYW1lPW1pbGt5X2NoYW5jZV8tX3N0b2xlbl9kYW5jZV8oemF5Y2V2Lm5ldCkubXAzO3NpemU9MTA1Mjc3MDM7dHlwZT1hdWRpbw==

Remove milky chance - stolen dance zaycev net.exe - Powered by Reason Core Security