tmcg8xwihbp4d.exe

AZOVEKOGRUP LLC

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application tmcg8xwihbp4d.exe by AZOVEKOGRUP has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the ProfitServis Downloader installer. The file has been seen being downloaded from oraudregy.drykwem.ru.
Publisher:
AZOVEKOGRUP LLC  (signed and verified)

Version:
1.0.0.0

MD5:
15505a3a9da42772425e1d520ca645a2

SHA-1:
04ceb92dadc80be4742ba40aa02f665dc8685f98

SHA-256:
e09368858c00da80f20d47c115005ed35090712eb1554d15aab0f41703a6b657

Scanner detections:
7 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
2/25/2025 2:28:52 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Clam AntiVirus
Win.Trojan.12408691
0.98/20138

Dr.Web
Trojan.InstallMonster.1052
9.0.1.05190

ESET NOD32
Win32/InstallMonstr.HI potentially unwanted application
7.0.302.0

K7 AntiVirus
Unwanted-Program
13.200.15148

Reason Heuristics
PUP.Bundler.ProfitServis
15.3.3.14

VIPRE Antivirus
Threat.4150696
38050

File size:
5.2 MB (5,403,976 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Bundler/Installer:
ProfitServis Downloader

Common path:
C:\users\{user}\downloads\tmcg8xwihbp4d.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
11/21/2014 4:00:00 AM

Valid to:
11/22/2015 3:59:59 AM

Subject:
CN=AZOVEKOGRUP LLC, O=AZOVEKOGRUP LLC, L=Marіupol, S=Wisconsin, C=UA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3177A159A9C4340E59630C167AA87721

File PE Metadata
Compilation timestamp:
6/20/1992 3:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:CmKfgL2/74cVyIuSW3P7DHMLHYCURMu6x9YX+3hgbbXuzh1wUUyS9RGe5l9o8nsG:CmKfdY+s7DHyHYCUZ6xWX+3hub+zh1Hs

Entry address:
0x75A3F0

Entry point:
60, BE, 00, 40, 6F, 00, 8D, BE, 00, D0, D0, FF, C7, 87, A4, F0, 3A, 00, 87, AE, 01, C4, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
4.4 MB (4,616,192 bytes)

The file tmcg8xwihbp4d.exe has been seen being distributed by the following URL.

Remove tmcg8xwihbp4d.exe - Powered by Reason Core Security