из к-ф-no_ya_skazal_leti_ot_berega_zamerzshego_leti.exe

Vkontakte DJ Installer

The application из к-ф-no_ya_skazal_leti_ot_berega_zamerzshego_leti.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from grot.appsflybeta.biz.
Product:
Vkontakte DJ Installer

Version:
1.9.1.26

MD5:
01c27677d47cf83200eb87196066dd38

SHA-1:
cd1f20353dc639f517dddeafb98d6e5d7b5aa1bd

SHA-256:
8b07cd8025d04eb96c4a60565ffc85afdc106f4463eba8cc78f0fb501c4a3ed3

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 9:33:57 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Downloader
7.1.1

Baidu Antivirus
PUA.MSIL.VKontakteDJ
4.0.3.16220

Dr.Web
Program.VKontakteDJ.10
9.0.1.051

ESET NOD32
MSIL/VKontakteDJ.A potentially unwanted (variant)
10.12779

Fortinet FortiGate
Riskware/VKontakteDJ
2/20/2016

Kaspersky
not-a-virus:Downloader.MSIL.VKontakteDJ
14.0.0.635

McAfee
Artemis!01C27677D47C
5600.6484

Sophos
Vkontakte DJLoader (PUA)
4.98

File size:
564 KB (577,536 bytes)

Product version:
1.9.1.26

Copyright:
Copyright © 2015

Original file name:
DjLoader.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\из к-ф-no_ya_skazal_leti_ot_berega_zamerzshego_leti.exe

File PE Metadata
Compilation timestamp:
11/10/2015 3:32:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:bXHBtFN4P7qsKQ0jnAt4BknkW3F2n3Cs0mhBtFC:jHJN4DBKQ0jnpBknk423CsRhJC

Entry address:
0x6AFFE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
420.5 KB (430,592 bytes)

The file из к-ф-no_ya_skazal_leti_ot_berega_zamerzshego_leti.exe has been seen being distributed by the following URL.