belote.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www.belote-online.com.
MD5:
690c3dcf42e1981baf84c0af5ac6dd35

SHA-1:
c19cd5984f7a2b4289151461c31e999fb3bcd3d3

SHA-256:
0f3296e48d253cffedd8126fbce2d552e0b7920fd210a5c8f33896d5e4ea7540

Scanner detections:
5 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
6/16/2024 1:41:47 PM UTC  (today)

Scan engine
Detection
Engine version

K7 AntiVirus
Riskware
13.212.18153

McAfee
Artemis!690C3DCF42E1
5600.6527

Total Defense
Heur/TrojanHorse.ZCIK!suspicious
37.1.62.1

Trend Micro
TROJ_GEN.R01TC0OFL15
10.465.07

VIPRE Antivirus
Trojan.Win32.Generic
45916

File size:
5.5 MB (5,809,664 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\belote.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:K7eVlR+ZN2VbYZx1FW2p0LAMQXzKg3IZtTbASdXdJxpW2txy:GeVf2Qcx134FqFgaaxpWo

Entry address:
0x1FD37E0

Entry point:
60, BE, 00, 10, E5, 01, 8D, BE, 00, 00, 5B, FE, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
5.5 MB (5,779,456 bytes)

The file belote.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ns376669.ip-94-23-250.eu  (94.23.250.77:80)

Scan belote.exe - Powered by Reason Core Security