vkontaktedj.exe

RECORD LLC

The application vkontaktedj.exe by RECORD has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from yoplayer.testtraff.ru.
Publisher:
VkontakteDJ  (signed by RECORD LLC)

Description:
Setup

Version:
1.3.0.0

MD5:
73a5e5a748e308707d56df14ddcce9ca

SHA-1:
f0af8700251deb58f31d9c7706cc7e6ab1ae0c7e

SHA-256:
e05e55e50a5dca73f41e0494b1eed225dc6d2fb0d10c9a7d9f82796a2c568dfd

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/30/2024 3:40:17 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.RECORD.Installer (M)
16.1.31.21

File size:
683.7 KB (700,088 bytes)

Product version:
3.65

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\vkontaktedj.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/17/2015 1:00:00 AM

Valid to:
2/17/2018 12:59:59 AM

Subject:
CN=RECORD LLC, O=RECORD LLC, STREET="Kolomyazhsky 33, liter A", L=Saint-Petersburg, S=Saint-Petersburg, PostalCode=197341, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
58EE01AAB8D97EDC88B98056655D1841

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:iH7ehYi+RySWqq55DI/imIj/lQZJJn78GVb3b0J9hQoF5JK:mFn/p6a/1saZJt7nVb3IJ9eJ

Entry address:
0x45D5E0

Entry point:
60, BE, 00, 90, 7D, 00, 8D, BE, 00, 80, C2, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
532 KB (544,768 bytes)

The file vkontaktedj.exe has been seen being distributed by the following URL.

Remove vkontaktedj.exe - Powered by Reason Core Security