win-7-home-torrent.exe

SysTracer v2.10

INTIS

The application win-7-home-torrent.exe by INTIS has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from torrent.zbkutgq5.bget.ru.
Publisher:
Blue Project Software  (signed by INTIS)

Product:
SysTracer v2.10

Version:
2.10.0.109

MD5:
9153fd393ec07db580a681bb5970fd6a

SHA-1:
be330c27195048c1b5ae12c93f2b8236f039d405

SHA-256:
83f0f4261ba9654f2e3ec4028ace0774f5a7fcf071bb53f03abd9ecd6e73455d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/6/2024 9:32:13 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.FileTour.INTIS (M)
16.7.10.5

File size:
2.2 MB (2,319,816 bytes)

Product version:
2.10.0.109

Copyright:
Copyright (C) 2007-2016

Original file name:
SysTracer.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\win-7-home-torrent.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/16/2016 3:00:00 AM

Valid to:
4/17/2017 2:59:59 AM

Subject:
CN=INTIS, O=INTIS, STREET="Prospekt 40-letija Pobedy, 69, 1, 8", L=Rostov-Na-Donu, S=RU, PostalCode=344072, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E0D42565A341BEBE1BAFBF6CA79F6420

File PE Metadata
Compilation timestamp:
10/18/1994 10:42:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:JXoq7CaCn/AZ6B+ujeVSdepKoWWrn+mZoNyUnK7EOdB1nYSKjNSri:pHfCnY6QujEScp3rn9ZoN2Zzri

Entry address:
0x649000

Entry point:
E9, 1E, 0A, 00, 00, 0C, E3, E3, 52, 68, F2, 03, E6, 7B, 9C, 81, 44, 24, 04, 66, 90, BE, 84, 9D, C3, DC, C8, F1, 68, 79, 94, A4, 00, 9C, FF, 4C, 24, 04, 9D, C3, 4F, 8B, 54, 24, 0C, E9, D9, 08, 00, 00, 04, 4D, 64, FF, 32, 68, 3A, 91, A4, 00, 9C, FF, 44, 24, 04, 9D, C3, 41, A4, B9, 5A, F8, 22, 01, E9, EE, 0E, 00, 00, D3, 16, 64, 8F, 05, 00, 00, 00, 00, E9, 2E, 0D, 00, 00, 61, 31, AF, C3, 68, 54, 92, A4, 00, C3, E1, FF, 64, FF, 35, 00, 00, 00, 00, 68, ED, 9C, A4, 00, C3, 58, 29, E9, AF, 05, 00, 00, A4, 8C, 68...
 
[+]

Packer / compiler:
Xtreme-Protector v1.05

Code size:
2 MB (2,054,144 bytes)

The file win-7-home-torrent.exe has been seen being distributed by the following URL.

Remove win-7-home-torrent.exe - Powered by Reason Core Security