undelete-360.exe

Undelete 360

Kirill Chermenin

The application undelete-360.exe, “Undelete 360 - Freeware” by Kirill Chermenin has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Undelete 360 FULL by File Recovery Ltd.. While running, it connects to the Internet address hz4.chermenin.com on port 80 using the HTTP protocol.
Publisher:
File Recovery Ltd.  (signed by Kirill Chermenin)

Product:
Undelete 360

Description:
Undelete 360 - Freeware

Version:
2.1.6.26

MD5:
0bb0b32ecde7e66c6d4caa698ea9168e

SHA-1:
66bbb0b6cec1230c4a7586f893db9b72ce1220ff

SHA-256:
75677ce9cb54459c47c202293d8184cb8caa84abce574a57500e1f34eaca7a65

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 3:30:41 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.KirillChermenin (M)
16.3.2.1

File size:
8.1 MB (8,534,920 bytes)

Product version:
2.1.6.26

Copyright:
Copyright, 2016 File Recovery Ltd.

Original file name:
undelete-360.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\file recovery\undelete360\undelete-360.exe

Digital Signature
Authority:
StartCom Ltd.

Valid from:
2/16/2016 4:31:22 PM

Valid to:
2/16/2018 4:31:22 PM

Subject:
CN=Kirill Chermenin, O=Kirill Chermenin, L=Krasnodar, S=Krasnodar Krai, C=RU

Issuer:
CN=StartCom Class 2 Object CA, OU=StartCom Certification Authority, O=StartCom Ltd., C=IL

Serial number:
6F0B658F0C30083E05B4646D6BE99928

File PE Metadata
Compilation timestamp:
3/1/2016 10:38:44 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:2NmT5KZL1K9f5aofN2Um8a71GRmRkRRRf2:24wKpQAN2Um8a7c/

Entry address:
0x6278F0

Entry point:
55, 8B, EC, 83, C4, EC, 53, 56, 33, C0, 89, 45, EC, B8, 04, 86, A1, 00, E8, C5, 90, 9E, FF, 8B, 1D, 64, A1, A5, 00, 8B, 35, F4, A2, A5, 00, 33, C0, 55, 68, 90, 7A, A2, 00, 64, FF, 30, 64, 89, 20, 8B, 0B, B2, 01, A1, C8, 14, A0, 00, E8, A1, 23, C0, FF, 89, 06, A1, F0, 9F, A5, 00, 8B, 00, BA, AC, 7A, A2, 00, E8, 96, 0B, FE, FF, 85, C0, 7E, 1B, A1, F0, 9F, A5, 00, 8B, 00, BA, AC, 7A, A2, 00, E8, 81, 0B, FE, FF, 8B, 15, 40, 9B, A5, 00, 89, 02, EB, 0B, A1, 40, 9B, A5, 00, C7, 00, 10, 27, 00, 00, 8D, 4D, EC, A1...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
6.1 MB (6,448,128 bytes)

The file undelete-360.exe has been discovered within the following program.

Undelete 360 FULL  by File Recovery Ltd.
www.undelete360.com
About 5% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to hz4.chermenin.com  (138.201.200.72:80)

TCP (HTTP):
Connects to ns1.ibspark.com  (54.72.130.67:80)

TCP:
Connects to ip-172-16-2-8.ec2.internal  (172.16.2.8:3128)

Remove undelete-360.exe - Powered by Reason Core Security