poisk.ws_1844526.exe

Premium Content Downloader

Grand Media LLC

The executable poisk.ws_1844526.exe has been detected as malware by 1 anti-virus scanner.
Publisher:
CNS Digital LLC  (signed by Grand Media LLC)

Product:
Premium Content Downloader

Version:
3.0.0.0

MD5:
3a37730086f21b259b9c1f6f71788cdb

SHA-1:
bb5da06ef3d953dad7569294982250a036eb8bb0

SHA-256:
71051e8f7a5ce397906a143ad7c9bbd324fdad3e3debb3e66f252f2b9bf2ba86

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/28/2024 12:51:10 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.14.23

File size:
985.8 KB (1,009,448 bytes)

Product version:
3.0.0.0

Copyright:
cnsdigital.com © 2015

Original file name:
assist

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\poisk.ws_1844526.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
11/20/2015 3:00:00 AM

Valid to:
11/20/2016 2:59:59 AM

Subject:
CN=Grand Media LLC, O=Grand Media LLC, L=Odessa, S=Odesskaya, C=UA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
5AC8EC5AB63DED6DD2CD90180631CA52

File PE Metadata
Compilation timestamp:
11/20/2015 6:32:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x1000

Entry point:
B8, 78, 95, 66, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 25, F7, 17, 7B, 9F, 4D, E2, 7E, D2, BB, 36, 34, D8, F3, D7, AF, 20, DC, FD, 1D, 94, 03, E7, 12, D3, A1, 0B, 16, 8F, EE, FD, 24, 28, AE, 69, 67, DE, 45, 3A, D5, ED, B0, 9C, 87, 40, 62, B4, F0, 95, DA, 0C, EF, B8, B1, 1D, 9D, 8A, 8F, FA, B6, D6, 00, B7, 06, 88, 8E, 33, 1F, 2D, 5E, 15, 7D, C6, 44, 2D, A2, 48, E9, A5, 7C, A5, DE, DC, 4F, 7C, 7C, 56, 4C, 6E, 5A, EA, F0, 94...
 
[+]

Packer / compiler:
PECompact v2

Code size:
1.5 MB (1,618,432 bytes)

Windows Firewall Allowed Program
Name:
poisk.ws_1844526.exe


Remove poisk.ws_1844526.exe - Powered by Reason Core Security