LLC

Publisher Information

LLC is a software publisher located in Odesa, 65074 in Ukraine*. The company is a primary distributor of unwanted software. Thre are 210 additional code signing certificates issued to this publisher.
Authority:
COMODO CA Limited

Valid from:
6/29/2015 7:00:00 AM

Valid to:
6/29/2016 6:59:59 AM

Subject:
CN="LLC ""SOFT DATA SISTEM""", O="LLC ""SOFT DATA SISTEM""", STREET="Bud. 71 kv. 167, vul.Marshala Malynovskogo", L=Odesa, S=65074, PostalCode=65074, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
038055a53cede11b348157aac339b85c

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Amonitize.OpenSource.Installer (M), PUP.Amonitize.OpenSource (M), PUP.Amonitize (M), PUP.Amonitize.OpenSour.Installer (M), PUP.Amonitize.Installer
100.00%

Dr.Web
Trojan.BtcMine.730
44.00%

Kaspersky
not-a-virus:HEUR:RiskTool.Win32.BitCoinMiner, UDS:DangerousObject.Multi.Generic, not-a-virus:RiskTool.Win32.BitCoinMiner
22.00%

Clam AntiVirus
Win.Trojan.Generickd-3949, Win.Trojan.Agent-954461
18.00%

AhnLab V3 Security
Unwanted/Win32.BitCoinMiner
18.00%

Panda Antivirus
Trj/Genetic.gen, Trj/CI.A, Generic Suspicious
14.00%

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen, HEUR/QVM11.1.Malware.Gen, Win32/Virus.RiskTool.cd6
14.00%

Quick Heal
(Suspicious) - DNAScan
12.00%

McAfee
Artemis!CC192C10399A
10.00%

SUPERAntiSpyware
PUP.BitCoinMiner/Variant, Hack.Tool/Gen-BitCoinMiner
6.00%

1 / 68      (Adware)
nsfff67.tmp (ETHM - Setup by Open Source)  (67654afc23ff7d88d1792d0b6564a988)

1 / 68      (Adware)
nsz820.tmp (Setup by Open Source)  (6862f4d7e7f1b7ae5d1be0bcacb1442d)

1 / 68      (Adware)
clinfo.exe  (4376415f3e19a7b3c1a9ae6019ac938d)

1 / 68      (Adware)
nsybbe1.tmp (ETHM - Setup by Open Source)  (15951b6aa486cc6e93368746ce18f2d3)

1 / 68      (Adware)
nshcc67.tmp (ETHM - Setup by Open Source)  (80073a3e9f0527a47b3e323b7c565b2f)

1 / 68      (Adware)
cpuminer-x86.exe (cpuminer)  (48f369a18e08a50be25729c40e1e7425)

1 / 68      (Adware)
clinfo.exe  (4709239d927455ea06ebb8629c48e6f8)

4 / 68      (Adware)

1 / 68      (Adware)
cpm.exe  (66da07d9b93c69b60ec9a8d902139aff)

1 / 68      (Adware)
clinfo.exe  (ceb0a11b0b295e0e32969cfcf38682f9)

1 / 68      (Adware)
nsi453e.tmp (Setup by Open Source)  (a895770239229d62839d8a6b169f8e58)

1 / 68      (Adware)
gpuminer-setup.exe (SG Miner - Setup by Open Source)  (8672667dfb3f6173e61362b356c57fed)

1 / 68      (Adware)
ethm.exe  (65d24ab47741da77b76a52a0f19ab247)

1 / 68      (Adware)
cpm.exe  (bcaa363d3dbf3c56d443f0e0a3749bcb)

1 / 68      (Adware)
clinfo.exe  (ce1549998d04979da606b5328dfaa231)

1 / 68      (Adware)
gpuminer-setup.exe (SGM - Setup by Open Source)  (28ecb2229c389bdc00ffe14390043f59)

1 / 68      (Adware)
cpuminer-x86.exe (cpuminer)  (3ede016138b42f3f7bb2813724faa09e)

1 / 68      (Adware)
clinfo.exe  (0072a5a21344efc534fd9f970f759a8d)

1 / 68      (Adware)
clinfo.exe  (1994e1bc4c2937a5d3ebe79e2a814474)

1 / 68      (Adware)
cpm.exe  (808b5c06b87ca5512e0b6fe57f0f4464)

1 / 68      (Adware)
cpuminer-x86.exe (cpuminer)  (ff1bbd69e29cc74f8fe2f6fdf1c43dff)

1 / 68      (Adware)
ethm.exe  (c6b64b323a8d43cd443259cfc1469104)

1 / 68      (Adware)
ethm.exe  (f9c2a1ebe4796e37ea2b9ebdccb87b71)

10 / 68    (Adware)
cdn.exe (ETHM - Setup by Open Source)  (88d99cc276990c57e19dcb8ca46b2348)

2 / 68      (Adware)
ethm.exe  (4d392f4f73575acf50dd1283095f0dd6)

2 / 68      (Adware)
ethm.exe  (a07b3c89ae018ca61dfdd771385fe1c3)

10 / 68    (Adware)
cdn.exe (ETHM - Setup by Open Source)  (8ab1215f5d7e6f9c3a404d6d20a695c1)

10 / 68    (Adware)
cdn.exe (ETHM - Setup by Open Source)  (29b82789993a0f83e7a12397a07b5ffa)

8 / 68      (Adware)
cdn.exe (ETHM - Setup by Open Source)  (98013023b7e6e139ea94d5498941b30c)

3 / 68      (Adware)
ethm.exe  (8b994358eabde4f90a0e13c3ab041775)

 
Latest 30 of 69 files

Downloads URLs for files signed by LLC .

8 / 68      (Adware)
http://113.171.224.210/.../Cdn.exe  (98013023b7e6e139ea94d5498941b30c)

6 / 68      (Adware)

5 / 68      (Adware)
http://113.171.224.244/.../Cdn.exe  (cee450052ff50b73f8202c90fc2868d4)

1 / 68      (Adware)
http://41.223.201.247/.../Cdn.exe  (7c80d3e37e8cf5974ca149fde9f1ec6d)

5 / 68      (Adware)
http://113.171.224.169/.../Cdn.exe  (cee450052ff50b73f8202c90fc2868d4)

5 / 68      (Adware)
http://zone2-14b7.kxcdn.com/Zone2.exe  (626a0e3e57f02629321664580557dc17)

1 / 68      (Adware)
http://installer-14b7.kxcdn.com/Installer.exe  (0e374c46a17ac0e18383529d5edd46c4)

10 / 68    (Adware)
http://cdn-14b7.kxcdn.com/Cdn.exe  (29b82789993a0f83e7a12397a07b5ffa)

The following websites host and distribute files published by LLC .

The certificates below are also signed by LLC .

00FE7B351079FD02F4C109D42C37F5C27A  (Jun 29, 2015 to Jun 29, 2018)

2A7DD7BCCEB648F185DD5A9432FE186D  (Oct 20, 2016 to Sep 04, 2017)

00F5EC479E1B7B3F9CEC13CFC8EDCC113C  (Sep 08, 2016 to Sep 03, 2017)

1A810FEC80052E26B932F3A315075709  (Aug 29, 2016 to Aug 30, 2017)

00F7244EEE637B20E588B65F59A244BFE1  (Aug 22, 2014 to Aug 22, 2017)

0CD9A2B4BA92EEB65DD3227ED6D3AF1E  (Jul 19, 2016 to Aug 22, 2017)

5A0289F4CB40DCA36F3E58617454A7C8  (Aug 01, 2016 to Aug 02, 2017)

20D09F2559BFDF0848AD8BC883379F18  (Oct 26, 2016 to Jul 23, 2017)

00CB1CD5925F9E2F5B0B456369E2C54C8B  (Jul 08, 2016 to Jul 09, 2017)

27DBE55E53BFEEB479C49E640598529F  (Aug 17, 2016 to Jul 09, 2017)

10 of 210 code signing certificates issued

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to LLC by COMODO CA Limited on June 29, 2015 with the serial number '038055a53cede11b348157aac339b85c'.