tom_clancys_the_division.torrent.exe

Astonsoft DeepBurner

MALITEK

The application tom_clancys_the_division.torrent.exe by MALITEK has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from s49e.storage.yandex.net.
Publisher:
Astonsoft  (signed by MALITEK)

Product:
Astonsoft DeepBurner

Version:
1.9.0.228

MD5:
97ca44a9234eb991ab2573243b546828

SHA-1:
8004b01531cf83bedc6859b51cd95dc477f5c6e7

SHA-256:
380e1439a4fcbf00a8236d043929c6c5ba5caec089fbfbe87598d270fa4681bf

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 6:24:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallMonster (M)
17.3.8.23

File size:
3.4 MB (3,585,992 bytes)

Product version:
1.8

Copyright:
Astonsoft (c) 2002 - 2006

Original file name:
DeepBurner.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\tom_clancys_the_division.torrent.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/26/2016 3:00:00 AM

Valid to:
3/13/2017 2:59:59 AM

Subject:
CN=MALITEK, O=MALITEK, STREET="Gazovikov, 30, 160", L=Tyumen, S=RU, PostalCode=625022, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A01AEAF9B16F1620ED4B82F942BD3FDC

File PE Metadata
Compilation timestamp:
7/6/2009 3:15:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x7505D4

Entry point:
55, 6A, 13, B9, EE, FC, 2F, 02, 33, C0, 03, 44, 24, FC, 49, 75, F9, FF, 15, B4, E3, B4, 00, BA, 40, 10, B5, 00, 42, FF, E2, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, BF, FD, 03, B5, 00, 81, C7, 12, 0C, 00, 00, 57, C3, EB, F1, 6A, 00, 58, 83, C0, 01, 33, DB, 8B, 88, 93, E1, B4, 00, 0F, B6, 09, 80, E9, B1, 83, E9, 07, 3B, CB, 75, 20, FF, 15, B0, E3, B4, 00, 6A, 64, FF, 15, FC, E1, B4, 00, E8, ED, FF, FF, FF, E4, E9, A9, 50, 57, 6A, 01, 8B, FF, EB, B8, 09, E4, E9, A0, 08, 00, 00, CA, 9A, 64, 89, 22...
 
[+]

Code size:
650.5 KB (666,112 bytes)

The file tom_clancys_the_division.torrent.exe has been seen being distributed by the following URL.

https://s49e.storage.yandex.net/rdisk/39886e70836624e0f41e54e0acab278181320caed30419ed81a276ec7068ea02/582f9386/NpouGkeqKno6nhH_pEmTkMLhuHHpAZZwdWOfYumxUs6Y_TPCCQ6FeSP3EHJC7J0Jte_Do4BTbdJqyzKyORulVA==?uid=432070496&filename=Tom_Clancys_The_Division.torrent.exe&disposition=attachment&hash=&limit=0&content_type=application/x-msdownload&fsize=3585992&hid=61c6f09e262f027c06e5bd40b3f4c060&media_type=executable&tknv=v2&etag=97ca44a9234eb991ab2573243b546828&rtoken=JfpHeOUbqyUU&force_default=yes&ycrid=na-6f0d09255089d33d1147fafa038170f3-downloader11h&ts=5419bf4c76d80&s=77910d81b536c0d0e89087a142fdd9a97db6531a29d1cf56df71335253d95fad&bp=/29/.../data-0.26:11032046324:3585992&pb=U2FsdGVkX1-MD0Zt5HA19i19cbfGcwWn3zuESLkWutCZ-GlpUjt0OdlqdbRShTjK7Y-L-B_IL-ogIsIQFPAVzhkcYQCI48wx48BthtBHkVY=

Remove tom_clancys_the_division.torrent.exe - Powered by Reason Core Security