quantum.break.pc.2016.eng.multi11.complete.collection.game.ultimate-1727-torrent.exe

Inar

The application quantum.break.pc.2016.eng.multi11.complete.collection.game.ultimate-1727-torrent.exe by Inar has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from downloader.disk.yandex.ru.
Publisher:
Inar  (signed and verified)

MD5:
66b64f29326c733ff19efd0469706e1b

SHA-1:
3fa384f721ad35f40ea4348f2acc7d3fd6453c7c

SHA-256:
e4805736e32de5de448d9b5e5365bb13ccd27eb90f4a7c47baf2ee19c10baf48

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 2:09:35 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.FileTour (M)
17.3.15.15

File size:
2 MB (2,127,840 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\quantum.break.pc.2016.eng.multi11.complete.collection.game.ultimate-1727-torrent.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/7/2016 2:00:00 AM

Valid to:
3/8/2017 1:59:59 AM

Subject:
CN=Inar, O=Inar, POBox=125430, STREET="Mitinskaya 28, 1", L=Moscow, S=Moscow, PostalCode=125430, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00AB4370BDD00A267992E2C4CE2CA93FB9

File PE Metadata
Compilation timestamp:
5/29/2010 2:05:57 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x602B0F

Entry point:
4D, 5A, 50, 00, 02, 00, 00, 00, 04, 00, 0F, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 1A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 50, 45, 00, 00, 4C, 01, 09, 00, 15, F5, 00, 4C, 00, 00, 00, 00, 00, 00, 00, 00, E0, 00, 03, 01, 0B, 01, 02, 19, 00, CC, 1E, 00, 00, 52, 00, 00, 00, 00, 00, 00, 0F, 2B, 60, 00, 00, 10, 00, 00, 00, 00, 0C, 00, 00, 00, 40, 00, 00, 10, 00, 00, 00, 02, 00, 00...
 
[+]

Code size:
1.9 MB (2,018,304 bytes)

The file quantum.break.pc.2016.eng.multi11.complete.collection.game.ultimate-1727-torrent.exe has been seen being distributed by the following URL.

https://downloader.disk.yandex.ru/disk/e64f2d98e37f6627d01b30ed6e3f5f0f464aa4eb24f9062a2aee3fa0e59bb0e0/57069459/.../x-msdownload&fsize=2127840&hid=4136679b280366e83fa50d2df1f7cbb2&media_type=executable&tknv=v2&etag=66b64f29326c733ff19efd0469706e1b