web freer 1.1 for windows _xp_ 7_ 8_ 8.exe

Smart Solyushns, TOV

The application web freer 1.1 for windows _xp_ 7_ 8_ 8.exe by Smart Solyushns, TOV has been detected as a potentially unwanted program by 2 anti-malware scanners. The file has been seen being downloaded from formedrawer.pp.ua.
Publisher:
Smart Solyushns, TOV  (signed and verified)

Version:
1.0.0.0

MD5:
f8d5d6d4719ecf09a0c81af9052f5436

SHA-1:
0187630389acdbf99e5db3f9a95160633d7b0410

SHA-256:
02df5cb235f3a1dabfe0d120f3231ef0285be9dbe1ac9d802c27540157689c08

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 12:09:46 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallMonstr.PE potentially unwanted application
8.0.319.0

Reason Heuristics
PUP.InstallMonster.SmartSol (M)
16.4.26.20

File size:
5.1 MB (5,353,320 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\web freer 1.1 for windows _xp_ 7_ 8_ 8.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/21/2016 5:00:00 AM

Valid to:
4/22/2017 4:59:59 AM

Subject:
CN="Smart Solyushns, TOV", OU=IT, O="Smart Solyushns, TOV", STREET="vul. Startova, 3", L=Dnipropetrovsk, S=Dnipropetrovska, PostalCode=49000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008AA4C6972211986EAE41368C3C5C8832

File PE Metadata
Compilation timestamp:
6/20/1992 3:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:LVoTsgdnTjMZxE8YUzVl1FgGGrmNHeZ4rzNJzgc8sHMOQ:WlnTjsYUzvjgGGrmNHH1JJ8x

Entry address:
0x200EE0

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, D8, 89, 45, D4, 89, 45, E4, 89, 45, E0, 89, 45, DC, 89, 45, E8, B8, 08, 04, 60, 00, E8, 4D, 6B, E0, FF, 33, C0, 55, 68, 0F, 16, 60, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E8, B8, 05, 00, 00, 00, E8, C2, D3, FF, FF, 8B, 45, E8, E8, 5E, 4A, E0, FF, 99, 89, 05, 64, 4F, 62, 00, 89, 15, 68, 4F, 62, 00, E8, 5C, C5, ED, FF, 99, 89, 05, 74, 4F, 62, 00, 89, 15, 78, 4F, 62, 00, E8, 4A, C5, ED, FF, 99, 03, 05, 74, 4F, 62, 00, 13, 15, 78, 4F, 62, 00, 71, 05, E8, 76, 30...
 
[+]

Entropy:
7.4305

Developed / compiled with:
Microsoft Visual C++

Code size:
2 MB (2,099,200 bytes)

The file web freer 1.1 for windows _xp_ 7_ 8_ 8.exe has been seen being distributed by the following URL.

Remove web freer 1.1 for windows _xp_ 7_ 8_ 8.exe - Powered by Reason Core Security