{blocked}.exe

Installer

Sub Zero LLC corp.

The application {blocked}.exe by Sub Zero corp has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from eu.simplesfile.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
New Monte Inc  (signed by Sub Zero LLC corp.)

Product:
Installer

Version:
1, 0, 1051, 1

MD5:
a2f1e13433c5da0f3e45062703e09982

SHA-1:
1ca6535ac22f37982093d1eefc24e0c215ba42e6

SHA-256:
21a2113fdaa429ba9aef5ed4bb73b3750843522d285bd70a96c125b768f9c4e3

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 2:33:00 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMonte (M)
17.3.16.10

File size:
3.2 MB (3,380,800 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2015

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\kasparov_-_pessa_pessa_hardcore_hooligan_mash_up_mp3.pm.mp3_downloader.exe

Digital Signature
Authority:
Sub Zero LLC corp.

Valid from:
12/15/2015 2:13:57 PM

Valid to:
12/14/2016 2:13:57 PM

Subject:
CN=Sub Zero LLC, OU=Sub Zero LLC corp., O=Sub Zero LLC corp., S=Copenhagen, C=DK

Issuer:
CN=Sub Zero LLC, C=DK, S=Copenhagen, L=Copenhagen, E=admin@subzerowin.com, OU=Sub Zero LLC corp., O=Sub Zero LLC corp.

Serial number:
100001

File PE Metadata
Compilation timestamp:
12/11/2015 10:26:58 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x704A75

Entry point:
68, 87, F4, EF, 4F, C7, 04, 24, 37, BE, 4E, 63, E8, 98, F9, D0, FF, 8D, 64, 24, 10, 0F, 84, 69, 4B, D1, FF, 68, E1, FA, C9, A6, 2C, 30, 60, 84, CE, 3C, 09, 9C, E9, 8E, BB, DC, FF, 0F, 83, 2E, 1D, FE, FF, 9C, 9C, 9C, 8D, 04, 83, E9, 45, B9, D0, FF, 8D, 64, 24, 04, E8, 91, 21, 00, 00, 60, 9C, 10, D2, 9C, 8D, 64, 24, 28, 0F, 83, AB, 20, D1, FF, F5, 5B, 66, 35, AB, 81, C0, E1, 02, 59, 66, 0F, A5, D0, 3F, 88, 55, FE, 0F, AB, D8, F6, DC, 83, F9, 04, 54, 88, 1C, 24, 0F, 9B, C0, 89, C8, E9, F0, 01, D1, FF, EF, 54...
 
[+]

Code size:
1.5 MB (1,588,224 bytes)

The file {blocked}.exe has been seen being distributed by the following URL.

https://eu.simplesfile.com/Kasparov_-_Pessa_Pessa_Hardcore_Hooligan_Mash_Up_mp3.pm.mp3_downloader.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove {blocked}.exe - Powered by Reason Core Security