8 skin pack for windows 7 tema v stile windows 8.exe

IT River

The application 8 skin pack for windows 7 tema v stile windows 8.exe by IT River has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from forces.upload-zone.ru.
Publisher:
IT River  (signed and verified)

MD5:
15da4d4edf849cf7c38f0f8c432b14eb

SHA-1:
9aefd15129a87cb99eca5ffac8184914102f998e

SHA-256:
954763c6f5178533a6b7e7bbfea32f744c2b86c18c3dc4e58713c4df101b49e9

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/25/2017 2:49:38 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ITRiver.q
14.7.27.13

File size:
553.9 KB (567,144 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\8 skin pack for windows 7 tema v stile windows 8.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/25/2014 4:00:00 AM

Valid to:
2/26/2015 3:59:59 AM

Subject:
CN=IT River, O=IT River, STREET="Obolenskiy, 9", L=Moscow, S=Moscow oblast, PostalCode=119021, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0F02E0C593A3B9A15B22F5853C90D66B

File PE Metadata
Compilation timestamp:
4/26/2014 2:31:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
26.23

CTPH (ssdeep):
6144:s6s4BAhus1cdFx0cveXFdjpwIa2ogl1Yh61kSTINYeXGUMRf+zQ+4:u42hTcEJ7jplZl31kf2Hr

Entry address:
0x8FED

Entry point:
C1, FF, 1A, 19, F0, 2B, 44, 24, 08, C1, F9, 1C, C1, D6, 16, FC, 41, C1, C2, 06, FC, 90, 8B, 74, 24, 0C, 42, 31, E5, 13, 0D, 50, 88, 41, 00, 90, 90, C1, E3, 0B, 33, 6C, 24, 08, 85, F2, C1, E6, 19, F5, 13, 4C, 24, 04, 03, 44, 24, EC, 89, CA, C1, FF, 18, FC, 87, EF, 33, 44, 24, F8, 0B, 04, 24, 85, 5C, 24, 0C, 47, 90, C1, E9, 09, 13, 54, 24, F0, C1, C5, 17, 81, 7C, 24, FC, FA, 54, CD, 9B, C1, EA, 0A, FD, 85, 54, 24, 0C, 81, C5, 5F, 1A, 9C, 4D, 33, 5C, 24, 04, 85, C7, 8B, 44, 24, 0C, 1B, 4C, 24, F0, 87, CF, F7...
 
[+]

Code size:
398 KB (407,552 bytes)

The file 8 skin pack for windows 7 tema v stile windows 8.exe has been seen being distributed by the following URL.