battlefield_2.exe

Installer

TAIMED LLC

The application battlefield_2.exe by TAIMED has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from amazingexperience.net. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
TAIMED LLC  (signed and verified)

Product:
Installer

Description:
Taimed

Version:
1.1.1.0

MD5:
6f8a0e32987ae0d3bd6cdec8fde69dc3

SHA-1:
7a17ba60e5ed51b5407de25c06e0530e7c4a3d2a

SHA-256:
8e26dc59e4101d4656fa4a2230673b01cc32d70dedd394b4f692d7dbaf24213b

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/24/2024 7:49:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.22.3

File size:
238.3 KB (243,984 bytes)

Product version:
1.1.1.0

Copyright:
Copyright 2015 TAIMED, All rights reserved.

Original file name:
instj.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\battlefield_2.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/10/2014 9:00:00 PM

Valid to:
6/10/2017 8:59:59 PM

Subject:
CN=TAIMED LLC, O=TAIMED LLC, STREET=Kirova st. 20A office 422, L=Moscow district, S=Lubertsy, PostalCode=140005, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00DC809665388D66359464C754C696D5C6

File PE Metadata
Compilation timestamp:
4/3/2015 6:44:29 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x17D8A

Entry point:
E8, 56, 7A, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, B0, F3, 42, 00, E8, 50, 4B, 00, 00, E8, B0, 3E, 00, 00, 0F, B7, F0, 6A, 02, E8, E9, 79, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 88, 47, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
157 KB (160,768 bytes)

The file battlefield_2.exe has been seen being distributed by the following URL.

http://amazingexperience.net/index.php?v=GGsLZdlzw6ZPktEX&channel=pbbt&fln=QmF0dGxlZmllbGRfMg==&t=1428085197&rnd=

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove battlefield_2.exe - Powered by Reason Core Security