OOO

Publisher Information

OOO is a software publisher located in Moskva, Russia*. The company is a primary distributor of unwanted software. Thre are 79 additional code signing certificates issued to this publisher.
Authority:
thawte, Inc.

Valid from:
2/17/2016 8:00:00 AM

Valid to:
2/17/2017 7:59:59 AM

Subject:
CN="OOO ""STROITELNO-TORGOVAJA KOMPANIJA ""KANT""", O="OOO ""STROITELNO-TORGOVAJA KOMPANIJA ""KANT""", L=Moskva, S=Moskva, C=RU

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
7fec5ef3224642c1430ae97a299b9390

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP (M)
100.00%

1 / 68      (Adware)
ts_10051.exe  (7774d2e0258edcef75fcf378dffc1657)

1 / 68      (Adware)
ts_10051.exe  (752f1b16949d11a70ce444d311cb6583)

1 / 68      (Adware)
sqlite3.dll  (93f9d2d638af76a6642800bde13a5e50)

1 / 68      (Adware)
uninstall.exe  (0ef9f4d07f325316348f6994ae9d6854)

1 / 68      (Adware)
sqlite3.dll  (8b990fa2de2a0564be1f486a4e3c2564)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
chromium.dll  (567f33a8f62792d2a8c9fc6de1e22166)

1 / 68      (Adware)
update10236.exe  (66cf0b84595a0a38d63dfa491175add1)

1 / 68      (Adware)
0538fab9_1060_crypt_io_copy.tmp  (cc69392e0070b3a6f386b045ee179da4)

1 / 68      (Adware)
2wq_gcm.dll  (8c2cd1b4e302ee06afd03c274b569fdf)

1 / 68      (Adware)
k3xoiuvsb5_m.dll  (33706b422fca8c0ca7bb1883520454e6)

1 / 68      (Adware)
k0hxrt2owwyj.dll  (fc1dc59a7effa7ce1316827beb0bb56d)

1 / 68      (Adware)
9nh6hjjh1tqk.exe  (12f346e8b932c051bcdec293c8242fc3)

1 / 68      (Adware)
update13528.exe  (2f4f43f16bdde778d1de6f664fc7ede0)

1 / 68      (Adware)
vtfpgtk.dll  (09d6d17b74a18cd835889981f2a7489f)

1 / 68      (Adware)
i9rsstt.dll  (068fa960d54fb9c196145dd442b3952d)

1 / 68      (Adware)
update12210.exe  (39c9d6dffa3faac31a67225049998d3f)

1 / 68      (Adware)
6lfk14xrbbad.dll  (8b6006bce86b518bb8e63639db8a8fe8)

1 / 68      (Adware)
bkvj9qy.dll  (7206422a8c0be97f11d05b08ddf13a56)

1 / 68      (Adware)
update27828.exe  (9d09e5342ba273f7ce8cbf5324f1d26a)

1 / 68      (Adware)
update19151.exe  (be3af927316ff84c35e00efc5f021a36)

1 / 68      (Adware)
update30815.exe  (ffb0ea6848333ebfc82edb28dcb2e1cd)

1 / 68      (Adware)

1 / 68      (Adware)
0gj5xvh.exe  (8a65c856bac7fb9cd634a4053e6893ee)

 
Latest 30 of 1,373 files

The certificates below are also signed by OOO .

09C2413E3B0CACE3E855A2C1A5CADBD6  (Mar 07, 2016 to Mar 08, 2019)

00E706CCD87DA6065486B42C0646C2DBF9  (Feb 11, 2016 to Feb 10, 2019)

5F5A06A7374A1B0B8DD3B08620FB7E8F  (Nov 27, 2015 to Dec 19, 2018)

009B0833F8AD9F393DF6B1E28AD4D38F9E  (Jun 09, 2016 to Jun 10, 2018)

00E2D0DD88AA54AE6A33646C36CF01E955  (Mar 23, 2015 to Mar 23, 2018)

6A96EA380826A911F2E88338A7053400  (Oct 18, 2016 to Oct 19, 2017)

00B526F3AAE3DA60C05A2E941DBACDBFF2  (Sep 28, 2016 to Sep 29, 2017)

79DB1629A125B1CDAA6C39B8A0B7360E  (Nov 09, 2016 to Sep 29, 2017)

00B633A6D77942DEBFF38D2DA2ABA75A23  (Jan 09, 2017 to Sep 01, 2017)

00BC4D5469B576BF5C92276B809D9303A6  (Aug 29, 2016 to Aug 30, 2017)

10 of 79 code signing certificates issued

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to OOO by thawte, Inc. on February 17, 2016 with the serial number '7fec5ef3224642c1430ae97a299b9390'.