vimeworld 17 07 2016 chity.exe

Windows Media Player Folder Sharing Executable

OOO

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application vimeworld 17 07 2016 chity.exe, “Windows Media Player Folder Sharing Executable” by OOO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from rufile.net.
Publisher:
Microsoft Corporation  (signed by OOO )

Product:
Microsoft® Windows® Operating System

Description:
Windows Media Player Folder Sharing Executable

Version:
11.0.5721.5262 (WMP_11.090130-1421)

MD5:
5d04365f7a767dea35cf6b39851c14fe

SHA-1:
27040864e608744f3f90f53aafd7f9e9ea30ac96

SHA-256:
e88760037a91c11a68989732734dcab1a3a07660ef158f1bc21b67ad98d93ca2

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/6/2024 2:03:43 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.7.18.7

File size:
922 KB (944,152 bytes)

Product version:
11.0.5721.5262

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
wmpshare.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\vimeworld 17 07 2016 chity.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/22/2016 4:00:00 AM

Valid to:
6/23/2017 3:59:59 AM

Subject:
CN="OOO ""Red Star Softvare""", O="OOO ""Red Star Softvare""", STREET="d. 51, ul.Magnitogorskaya", L=Saint Petersburg, S=Leningradskaya, PostalCode=195027, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7DA07100EA6431E3EC00743E0907E3C2

File PE Metadata
Compilation timestamp:
7/15/2016 11:25:52 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:ZMHHUZ3o4wqhu9NxnflSxSXSjGfW4Tg+x5AHkJRSqlXs:Zc0Z4j4xYLN1xS+SqlXs

Entry address:
0x1030

Entry point:
55, 8B, EC, 81, EC, 20, 04, 00, 00, 68, 4C, 40, 4D, 00, FF, 15, 0C, 80, 4B, 00, 68, 54, 40, 4D, 00, FF, 15, 0C, 80, 4B, 00, 68, 5C, 40, 4D, 00, FF, 15, 0C, 80, 4B, 00, 68, 64, 40, 4D, 00, FF, 15, 0C, 80, 4B, 00, 68, 6C, 40, 4D, 00, FF, 15, 0C, 80, 4B, 00, 68, 74, 40, 4D, 00, FF, 15, 0C, 80, 4B, 00, 68, 7C, 40, 4D, 00, FF, 15, 0C, 80, 4B, 00, 68, 84, 40, 4D, 00, FF, 15, 0C, 80, 4B, 00, 68, 8C, 40, 4D, 00, FF, 15, 0C, 80, 4B, 00, 68, 94, 40, 4D, 00, FF, 15, 0C, 80, 4B, 00, 8B, 45, EC, 69, C0, 56, A0, EC, 11...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
730.5 KB (748,032 bytes)

The file vimeworld 17 07 2016 chity.exe has been seen being distributed by the following URL.

Remove vimeworld 17 07 2016 chity.exe - Powered by Reason Core Security