searchisc-sus.ru_cis.exe

ITEA LLC

The application searchisc-sus.ru_cis.exe by ITEA has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
ITEA LLC  (signed and verified)

MD5:
536caaad04f0d5e6f06a4d14a79fcf68

SHA-1:
03de37ec995d8b97e2d69d9ca2211a8c1de9c72d

SHA-256:
3bb8ba7041be5b719c50df13658aaa9ef18924b8854937c5c381f9b4e24be0bb

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 3:21:51 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.HomePageDef.ITEA (M)
16.6.9.0

File size:
289.7 KB (296,624 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\searchisc-sus.ru_cis.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/18/2016 2:00:00 AM

Valid to:
2/18/2017 1:59:59 AM

Subject:
CN="""ITEA"" LLC", OU=IT, O="""ITEA"" LLC", STREET="prosp. Vyzvolyteliv, 5", L=Kiev, S=Kiev, PostalCode=02660, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
277A5AD5AF3F7ADB181C76A58924E916

File PE Metadata
Compilation timestamp:
3/18/2016 3:34:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
6144:uht8UcDD1Z9gG2Lo3vmFOETaFdwcS5E9fHleHDbyLcWZxA:uz8fD5Z9gZoDbwcSq9fgDRWE

Entry address:
0x4141

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, 2C, 08, 00, 00, 31, DB, E8, A0, 7A, 00, 00, 89, A5, 58, F9, FF, FF, 83, EC, 30, 89, D8, FC, 8D, 74, 24, 0F, 83, E6, F0, 89, F7, AB, AB, AB, AB, AB, 6A, 00, 6A, 00, 6A, 00, 6A, 00, 6A, 0A, 56, 6A, 00, 6A, 00, E8, 2A, 7A, 00, 00, 85, C0, 74, 14, 6A, 00, 6A, 00, 6A, 00, 6A, 00, 6A, 0A, 56, 6A, 00, 6A, 00, E8, 12, 7A, 00, 00, FC, 8D, 95, 80, FC, FF, FF, 89, D8, 89, D7, 8B, A5, 58, F9, FF, FF, AB, 83, EC, 30, AB, 8D, 7C, 24, 0F, 83, EC, 30, 83, E7, F0, AB, AB, AB, AB, AB, 8D, 7C...
 
[+]

Code size:
44.5 KB (45,568 bytes)

Remove searchisc-sus.ru_cis.exe - Powered by Reason Core Security