amigo_dkit.exe

Mail.Ru Launcher

Mail.Ru LLC

The application amigo_dkit.exe by Mail.Ru has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from pdownload.amigo.mail.ru. While running, it connects to the Internet address moscow.cdnmail.ru on port 443.
Publisher:
Mail.Ru  (signed by Mail.Ru LLC)

Product:
Mail.Ru Launcher

Version:
3.9.0.1

MD5:
67e397a9636a11a726cbb1c7309ea494

SHA-1:
3cbc2c8ecaea7e6080d2d95abec538cc8bcb054d

SHA-256:
44d75f73e0a0f31f0be17903af8d2788518b73d331eb63dd9684906d9c5c214a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/9/2025 12:22:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Bundler (M)
17.3.4.13

File size:
154.6 KB (158,352 bytes)

Product version:
3.9.0.1

Copyright:
Copyright 2015

Original file name:
launcher.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\amigo_dkit.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
7/6/2016 3:00:00 AM

Valid to:
7/7/2017 2:59:59 AM

Subject:
CN=Mail.Ru LLC, O=Mail.Ru LLC, L=Moscow, S=Moscow, C=RU

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
16F89FF5A6CD11A76E9963DAC485D65F

File PE Metadata
Compilation timestamp:
9/23/2016 11:27:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x9453

Entry point:
E8, A6, 73, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 57, 83, CF, FF, 85, F6, 75, 14, E8, AA, 28, 00, 00, C7, 00, 16, 00, 00, 00, E8, 42, 50, 00, 00, 0B, C7, EB, 45, F6, 46, 0C, 83, 74, 39, 56, E8, FA, 00, 00, 00, 56, 8B, F8, E8, 14, 75, 00, 00, 56, E8, EA, 74, 00, 00, 50, E8, C5, 07, 00, 00, 83, C4, 10, 85, C0, 79, 05, 83, CF, FF, EB, 13, 83, 7E, 1C, 00, 74, 0D, FF, 76, 1C, E8, 0F, FC, FF, FF, 83, 66, 1C, 00, 59, 83, 66, 0C, 00, 8B, C7, 5F, 5E, 5D, C3, 6A, 0C, 68, 98, 15, 42, 00, E8, 1B, 35...
 
[+]

Code size:
96.5 KB (98,816 bytes)

The file amigo_dkit.exe has been seen being distributed by the following URL.

https://pdownload.amigo.mail.ru/.../amigo_dkit.exe

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP SSL):
Connects to moscow.cdnmail.ru  (94.100.180.110:443)

Remove amigo_dkit.exe - Powered by Reason Core Security