SOSVirus

Publisher Information

SOSVirus is a software publisher located in Valence, France*. Thre are 6 additional code signing certificates issued to this publisher.
Authority:
SOSVirus

Valid from:
2/24/2015 4:13:07 PM

Valid to:
2/23/2017 4:13:07 PM

Subject:
CN=g3n-h@ckm@n, OU=26, E=gen-hackman@hotmail.fr, O=SOSVirus, L=Valence, S=France, C=FR

Issuer:
CN=g3n-h@ckm@n, OU=26, E=gen-hackman@hotmail.fr, O=SOSVirus, L=Valence, S=France, C=FR

Serial number:
00d813f6

Status:
Inconclusive detections from multiple engines

Scan engine
Details
Detections

Rising Antivirus
PE:Backdoor.Win32.DarkKomet.b!1075356506, PE:Trojan.Win32.Injector.fw!1075357566, PE:Backdoor.Win32.Gbod.b!1075358427
40.00%

Bkav FE
W32.HfsAtITA
24.00%

Qihoo 360 Security
Win32/Trojan.d4d, HEUR/QVM10.1.Malware.Gen
24.00%

Zillya! Antivirus
Trojan.Bladabindi.Win32.43997
16.00%

avast!
Win32:Evo-gen [Susp], Win32:Malware-gen
12.00%

Reason Heuristics
Threat.Win.Reputation.IMP
12.00%

IKARUS anti.virus
Trojan.Agent, Trojan.AD.PrivacyCenter
8.00%

Trend Micro House Call
Suspicious_GEN.F47V0301, Suspicious_GEN.F47V0228
8.00%

Avira AntiVirus
TR/AD.PrivacyCenter.M.2, TR/AD.PrivacyCenter.M.7
8.00%

McAfee
Artemis!C357C44BE2CD
4.00%

0 / 68
winlogon.exe (by SosVirus)  (6c9d4b85e0277d615cb3231f61667fd7)

0 / 68
winlogon.exe.egt (by SosVirus)  (71238c0a6df65d54dcf8ec391589af81)

1 / 68      (inconclusive)
processclose.exe (by SosVirus)  (219ce2b6c5966ef16e0e6d66a40ea71d)

0 / 68
pre-scan_5.02.26.1.exe  (1f3a1c3fe6e28738d527a258548eef27)

1 / 68      (Malware)
pre-scan_6_24.02.2016.1.exe (by SosVirus)  (4c47cadc5b6a17c73473f6d2b95a0418)

1 / 68      (Malware)
pre-scan_5_27.12.2015.1.exe (by SosVirus)  (f8e891679effe93b6e6215cf7b32453d)

1 / 68
pre_scan.exe (by SosVirus)  (b624b839f22a1648d343505fde165578)

1 / 68      (Malware)
pre-scan_6_05.01.2015.1.exe (by SosVirus)  (564f86de78fb95274fb22755e63755df)

2 / 68
pre-scan_5_10.12.2015.1.exe (by SosVirus)  (37ac9f6ceb18bd114fec0c5d641f62e7)

2 / 68
pre_scan.exe (by SosVirus)  (a8c933906b6a56de6327c55c394e0c8f)

4 / 68      (Malware)
pre_scan.exe (by SosVirus)  (05801028aecec4f5b524fa3a826f873d)

3 / 68
winlogon.exe (by SosVirus)  (2821a369ca8c4a9a48b9cf04da004134)

2 / 68
winlogon.exe (by SosVirus)  (536db19d42abbb8e30b7cf4c0c2c9bfa)

0 / 68
pre_scan.scr (by SosVirus)  (d67e3e242a122449ddafd03ab9f44584)

0 / 68
pre_scan.pif (by SosVirus)  (9f4b5b134100c7fb4a866ac6f462edbf)

0 / 68
pre_scan.com (by SosVirus)  (46dadf89b0c4feb47fc9cc79742a9308)

1 / 68
processclose_1.0.0.2.exe (by SosVirus)  (a7f966265fca5d1a58ca74722c3576ca)

0 / 68
pre_scan.exe (by SosVirus)  (d5d08f2f7814faf708fec34228130eb2)

0 / 68
pre_scan.exe (by SosVirus)  (ddf79bf849256e8144d21849f096e465)

2 / 68
malware - processclose v.1.0.0.1.exe (by SosVirus)  (31bdb422ad891b0c9a28fa9e977fb71f)

0 / 68
pre-scan_5_16.08.2015.1.exe (by SosVirus)  (ca66464f3f14c8c87d3f60f1c86e5e11)

0 / 68
pre-scan_5_14.08.2015.2.exe (by SosVirus)  (250166956a5dc14d4026189a1e911e3b)

7 / 68      (PUP)
pre_scan.exe (by SosVirus)  (e7bfc8fa7430906487d361ec2b06da1f)

0 / 68
pre-scan_5_05.08.2015.1.exe (by SosVirus)  (b0a256d609d7fb0e23139ee27c82dc7c)

1 / 68
pre_scan.exe (by SosVirus)  (5a025d5c0754af5cfc3436a7669f0c2d)

0 / 68
pre_scan.exe (by SosVirus)  (4e57490fbdfcf7cc6e3c8e7386282c7c)

1 / 68
pre-scan_5.02.27.1(portable).exe (by SosVirus)  (559599ca44b04e9a7f90ebee0c96e111)

1 / 68
non confirmé 801765.crdownload (by SosVirus)  (5149c3d7268bda75ad3343f742919217)

1 / 68
pre_scan_restore.exe  (c0bd6dda319485b64b44f04a83cec1bc)

1 / 68
pre_scan.exe (by SosVirus)  (197cad442e7b9434febd4bd0a6d3a364)

 
Latest 30 of 39 files

Downloads URLs for files signed by SOSVirus.

1 / 68      (Malware)
https://toolslib.net/downloads/finish/68/get/.../  (pre-scan_6_24.02.2016.1.exe)

0 / 68
https://toolslib.net/downloads/finish/68/get/.../  (pre-scan_5_05.08.2015.1.exe)

The following websites host and distribute files published by SOSVirus.

The certificates below are also signed by SOSVirus.

049D58E8  (Jun 30, 2016 to Jun 30, 2018)

4A75CFE56B31FD2178DCAEA9  (Feb 23, 2017 to Feb 24, 2018)

046E4126  (Jan 05, 2016 to Jan 04, 2018)

030675ED  (Nov 26, 2015 to Nov 25, 2017)

0379618C  (Feb 24, 2015 to Feb 23, 2017)

00C0D287  (Feb 23, 2015 to Feb 22, 2017)

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to SOSVirus by SOSVirus on February 24, 2015 with the serial number '00d813f6'.