uran.exe

Uran

Limited Liability Company Ucoz Media

The application uran.exe by Limited Liability Company Ucoz Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address srv226-131.vkontakte.ru on port 80 using the HTTP protocol.
Publisher:
uCoz Media LLC and Chromium Authors  (signed by Limited Liability Company Ucoz Media)

Product:
Uran

Version:
32.0.1700.77

MD5:
49e6022e472d7920e45f84bc6fd05e49

SHA-1:
c1320d57af3606e2ec9ffbbaafd5541a26f94c3a

SHA-256:
cc58e4ce5a8c4773a35521250d36413015c5fe62d2354bfec04c72cc401f3744

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 12:30:11 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.LimitedLiabilityCompanyUcozMedia
15.3.20.18

File size:
827.5 KB (847,312 bytes)

Product version:
32.0.1700.77

Copyright:
Copyright 2013 uCoz Media LLC Chromium Authors. All rights reserved.

Original file name:
chrome.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\ucozmedia\uran\application\uran.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/29/2014 8:05:40 PM

Valid to:
4/17/2015 11:17:49 PM

Subject:
E=alexzander@ucoz.com, CN=Limited Liability Company Ucoz Media, O=Limited Liability Company Ucoz Media, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112151EB6FD5329EE6DCAEC03C522243C994

File PE Metadata
Compilation timestamp:
2/5/2014 6:05:55 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:brSj7oXhRsK2CE4AdmVu9//ZIt1LjxxQQa:iErR22ASu9XZIzLjxxW

Entry address:
0x54103

Entry point:
E8, 6B, BA, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, 35, E8, 32, 47, 00, 57, FF, 35, 14, 65, 4A, 00, FF, D6, FF, 35, 10, 65, 4A, 00, 8B, D8, 89, 5D, FC, FF, D6, 8B, F0, 3B, F3, 0F, 82, 81, 00, 00, 00, 8B, FE, 2B, FB, 8D, 47, 04, 83, F8, 04, 72, 75, 53, E8, C1, BA, 00, 00, 8B, D8, 8D, 47, 04, 59, 3B, D8, 73, 48, B8, 00, 08, 00, 00, 3B, D8, 73, 02, 8B, C3, 03, C3, 3B, C3, 72, 0F, 50, FF, 75, FC, E8, F1, 4B, 00, 00, 59, 59, 85, C0, 75, 16, 8D, 43, 10, 3B, C3, 72, 3E, 50, FF, 75, FC, E8...
 
[+]

Code size:
454 KB (464,896 bytes)

Shell Open Command
Open type:
ftp

Command:
"C:\users\{user}\appdata\local\ucozmedia\uran\application\uran.exe" -- "%1"


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to yandex.ru  (93.158.134.11:80)

TCP (HTTP):
Connects to videohosting  (195.239.242.48:80)

TCP (HTTP):
Connects to vh2.ilser.by  (46.165.235.3:80)

TCP (HTTP):

TCP (HTTP):
Connects to titanik.itmm.ru  (195.239.242.29:80)

TCP (HTTP):
Connects to terminator.itmm.ru  (195.239.242.27:80)

TCP (HTTP):
Connects to stde5.fornex.org  (5.187.7.26:80)

TCP (HTTP):
Connects to static5.fishgame3d.com  (31.186.101.130:80)

TCP (HTTP):
Connects to stakan.itmm.ru  (195.239.111.162:80)

TCP (HTTP):
Connects to srv99-131.vkontakte.ru  (87.240.131.99:80)

TCP (HTTP):
Connects to srv98-131.vkontakte.ru  (87.240.138.98:80)

TCP (HTTP):
Connects to srv97-131.vkontakte.ru  (87.240.131.97:80)

TCP (HTTP):
Connects to srv95-131.vkontakte.ru  (87.240.133.95:80)

TCP (HTTP):
Connects to srv82-131.vkontakte.ru  (87.240.183.82:80)

TCP (HTTP):
Connects to srv53-131.vkontakte.ru  (87.240.183.53:80)

TCP (HTTP):
Connects to srv251-131.vkontakte.ru  (87.240.157.251:80)

TCP (HTTP):
Connects to srv242-131.vkontakte.ru  (87.240.143.242:80)

TCP (HTTP):
Connects to srv226-131.vkontakte.ru  (87.240.134.226:80)

TCP (HTTP):
Connects to srv225-197.vkontakte.ru  (95.142.199.225:80)

TCP (HTTP):
Connects to srv217-182.vkontakte.ru  (87.240.182.217:80)

Remove uran.exe - Powered by Reason Core Security