buon giorno bell anima.exe

Mobilnye Proekty , Ooo

The application buon giorno bell anima.exe by Mobilnye Proekty , Ooo has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from forces.kubaniniman.ru.
Publisher:
Mobilnye Proekty , Ooo  (signed and verified)

MD5:
12c698389cb70dea0ce5631d918776de

SHA-1:
b702a15716ae7555b7060c382b0177926e71b955

SHA-256:
098e3f027f0e17ff1fbc713bbe6f7e057146cdac4d48bb2de37b321e8dadb9af

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 10:20:12 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.11.18

File size:
481.9 KB (493,464 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\buon giorno bell anima.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/21/2014 2:00:00 AM

Valid to:
5/22/2015 1:59:59 AM

Subject:
CN="Mobilnye Proekty , Ooo", O="Mobilnye Proekty , Ooo", STREET="Tymenskaya 5, bld. 1", L=Moscow, S=Moscow region, PostalCode=107370, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D812EDF6481CAD30D5A8D2B9E47437D4

File PE Metadata
Compilation timestamp:
5/31/2014 10:05:44 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
27.26

Entry address:
0x997C

Entry point:
2B, 1D, 8E, E8, 40, 00, BD, D9, ED, 0E, 8B, 1D, 86, 70, 3B, 82, 19, D2, F5, 81, E5, 54, FB, 94, 0A, 90, 33, 2D, 66, 96, 44, 00, C1, E5, 16, D1, F9, 23, 6C, 24, FC, 13, 2C, 24, 45, 39, D4, 1B, 6C, 24, 14, C1, D5, 1E, 93, 8B, 4C, 24, 10, C1, C3, 14, C1, C7, 0C, F7, 44, 24, F4, 4E, 84, 76, 26, C1, E2, 17, F7, D1, C1, E2, 18, C1, E6, 0C, C1, FA, 1F, C1, FE, 17, C1, D1, 19, 43, 19, F7, C1, DB, 06, 1B, 54, 24, F8, 85, DA, 13, 35, 07, 4C, 40, 00, F7, D5, F5, 11, FD, FD, C1, C3, 19, 90, 81, CA, A6, C4, 6E, B0, F7...
 
[+]

Code size:
398.5 KB (408,064 bytes)

The file buon giorno bell anima.exe has been seen being distributed by the following URL.

http://forces.kubaniniman.ru/NTM2NTtodHRwJTNBJTJGJTJGenZ1a29mZi5ydSUyRmRvd25sb2FkJTJGMjYwMDQ5OTtuYW1lPUJ1b24rR2lvcm5vK0JlbGwlMjdhbmltYTtzaXplPTEwMjYwNDgwO3R5cGU9YXVkaW8=

Remove buon giorno bell anima.exe - Powered by Reason Core Security