sai russian pack v1.exe

Tohekat

SpeedyPrompt (New Media Holdings Ltd)

The application sai russian pack v1.exe, “Tohekat Setup ” by SpeedyPrompt (New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.newtourshare.com and multiple other hosts.
Publisher:
Kup   (signed by SpeedyPrompt (New Media Holdings Ltd))

Product:
Tohekat

Description:
Tohekat Setup

Version:
4.8.4.0

MD5:
c9404ec254d84df6f5b3ab84d2a196e5

SHA-1:
499a3a5f889e49b218b6bb60aba22347ef12149b

SHA-256:
09d0c16cce13b8a4c08c8670a00dc7672554977dd623ee480769043d0c13b00c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 8:16:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.NMH.Bundler (M)
16.3.16.17

File size:
951.1 KB (973,912 bytes)

Product version:
4.2

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\sai russian pack v1.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 4:27:56 PM

Valid to:
6/1/2016 6:18:59 PM

Subject:
CN=SpeedyPrompt (New Media Holdings Ltd), O=SpeedyPrompt (New Media Holdings Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11217859832E1C02CFE81458CC264243B14E

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Y7MtbV/r2oxmgWeLEYb2VxnJ+cCkCMm4xQuM:YwX/r2YmHIMxY34xQD

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file sai russian pack v1.exe has been seen being distributed by the following 26 URLs.

http://www.newtourshare.com/w9YqFOyosEzfO24vIgEIDmkjfXgim8KIbHE6eqL3r8uJLFHtZIHFb614N_msFgf3jVrK5HyEFGCxZYK3mjUIzpy5GNUMsu9zRCGwFvFs5znzsVqMYxCp7WNcLQxIH3ajWL_AGWCTyL71E2dELpJLBxOJvtnKb84ojhCJKSCMGHlqer6Ij7uqQDk_R9_tvEBj6JdJpI_0YrHNWiYqbm5QmYPGNX3Wz1XesBAy0QRsJwzyBcqhZLFcX1uANC1_cseq0n7BHFbAS8XyAYAK4dJxGh4xKJrA3bj6UWHQjqXyVWQuE8YzSP5skoAPla1QdBja2rBMh4nm1pr4bq4VvYK3aJkn1OSKWOChqf rNpXWxnQ7b_rsFfg=-Gx4AAAQccmiptINUUAtSyCa66I3zQN4Y WRVY5yNThw=

http://www.newtourshare.com/qF3fhnYZVCcDUwWemQYpymh9iHeiyYhGAqOnuAGb8WT_TV_l7vrAoxFx7hnBnEzg5UfvLv28AEiHvroeygvQY1nOX9_Mz2oimHypRnsJzAn00aFCLP4kCjy qPgAcB3Qrskh2YvrXPv3kWo0OxxmdW T1SYXtpHe5c8OlVXHERN7Pm6Nluq0hqScHaU4cmKWNaVWHSw_MfTclWerL_3WSjrh8Kl5pz0hmpUzAGnKlGGS2Cw0cTkZASmLx_DdIxsTLMk8O6Kx6uxRnDbf1SkfytQ95k0rIQjLuJGDNCok3B8X7EzdLq_GuL1FFuSu3J_EFEDj7vD319qruuRqFatC8oX4O3m slMy m8BCx4_N0SPSM5usac=-Gx4AAAQccmiptINUUAtSyCa66I3zQN4Y WRVY5yNThw=

http://www.newtourshare.com/TxghqceugvK85ZtISOGPR_Gg1QdJql3YvNsEXGm_SSeJBbbOJEL0QelCeLvjRjNHsXDnajFUZbu2K560HmubwvCxI5NMWlY_G8vRE3MWOtMIVe4qDAJtUMqkmTo8q2zJN6Maj0apoeVvgsltMhMKaFl8_xaSz1Wd3o_eMG30ceSdYYbu 1iVk_cWOFYXRSjojLSmppy3DNTg3ynfABGJ4Q15XhxiKi uKltjQiMitX5Ha8XAspsRxPLSXNjqfK0oFRtx PN8J vqFKammZ_vi0MT1it9aik_XQx5HqFN sXRYHQ4Bx4q2pEGOdlmNZ sJo9kdRQplXkuyd11Dc9m1QQPqvIRdsjhpdccPxShCr1_iOeRE18=-Gx4AAAQccmiptINUUAtSyCa66I3zQN4Y WRVY5yNThw=

http://www.newtourshare.com/Bocw41K4nCQfDoWWo7e GQ5rvEabc8j V9CR2h guNhsqpNugmJlM1V1eEy78YTRfbu8HZkGOypqVU61Wu8zhYCIC6uaZRfvGWEvC0IIaHwpxD5M7GkKmVDo5w2I42lkk4xFmnLSO72DdJHIhmK6_GlA8BOiUvyU58o4yjS9yKEMFF9d85LH5MbehZEeWp0h4YwcwVjU475SdPLDb9S0J4sRJDEvs43NxxPgRH0oKzjIJsqH5nfsYLk4tqzmHFBOH5era5iqjHY3JGxme3AbMKQgjLlnXWn34SfrMhp2p4ERGjwR2r0MwDb3RxAOJ9Z1eouEYr2wOgYYERcj0 vZxrlVtkWXEttxoRtxDa0veYhU8dTF8dM=-Gx4AAAQccmiptINUUAtSyCa66I3zQN4Y WRVY5yNThw=

http://www.newtourshare.com/c?x=RHqDCdvP4Pl/72OKEd3Vy0ovo00KodpAE7p19i1UwF8=&c=7rlspo3OVW 9PJOCWw0CVK9YfP8HJbFmW0KdoKCyjNmPfbziIUOmxAsanc wKGWwrWam7fORoi4Ii2ilt6MXYKxB0usRcz3dmpSmide/PUi5YhDeZyw2HQxBWmJdUUVQ&downloadAs=SAI Russian Pack v1.exe&fallback_url=http://.../test.exe

http://www.newtourshare.com/6eauUe7zcx9EktPXNh1d5_p2YqU3p5BKOV5ujY7KQFZo9LbLhZJpnOruN8WhI02pA6aigWiXR9tnN7a_lznJFt48EiXvmMcDA6rAyV37Ssb8tTeBoUi4_eXts1fSSPS7KA2UWpvs4G3lT5zDikmWfKtNaCkq IK3GlULcOl24qFQJ uAqLpBwJVRx8iD0TcJwPk4E7iYjW7c2660Iq4zNt_zC3vRpSvOH9uW6glBHAphSvP mLrTvFHtDpmSuKCrlAqcxSex5YTU0tbR8qVuIHDPKabNB2NfzUABl4JCMbWI2BCGfPDmKGqy0qo6aSxDTdVBflb6O5K1B_ceKfLHmRJ9RCwDfDTKc0c2eFsU1dHTb_RNr5Y=-Gx4AAAQccmiptINUUAtSyCa66I3zQN4Y WRVY5yNThw=

http://www.newtourshare.com/Y4 sqsLqJztDVq7Bnxzs0CdXrGDk1uPdmzOTXoT9VADjfBNg6lIta8THo1CtIvj8_icp1kpac_rlyHfOycqNxf6gS1eX6A_2L B9StAhsRv3ABlJgE2Ok03u97qhv0E0MzXV2Js2LyLDXctNGIoHdR_1GhJ9j4POhTnsbk6kWp8G5w8nGFurvB5XgVA1pFyBR04OEpX559Dkof222C8AVZTyJkh_rnKAqCO86zQVstVvk5COnMP7juVGEQBvg UqAgMKzsDv3IzyDSJ_zjmSY9 Vwmf9GC TxlQnRxYJ69TE1ld1pZ61R6_8U9UFYM b54ArE0s5ZJI6XHO2HDEgDuD uPw73nCbpRkIWB1Vh6vVDFCvInQ=-Gx4AAAQccmiptINUUAtSyCa66I3zQN4Y WRVY5yNThw=

Remove sai russian pack v1.exe - Powered by Reason Core Security