edmond ayvazyan ev arman papoyan - de asa de xosa -- armenian pop -- hf exclusive -- hd.exe

Vkontakte DJ Installer

The application edmond ayvazyan ev arman papoyan - de asa de xosa -- armenian pop -- hf exclusive -- hd.exe has been detected as a potentially unwanted program by 20 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from setup.vk-dj.com and multiple other hosts. While running, it connects to the Internet address ip-static-94-242-221-153.server.lu on port 80 using the HTTP protocol.
Product:
Vkontakte DJ Installer

Version:
1.9.0.9

MD5:
fe69757baeba40b705674f7623ae5cc6

SHA-1:
3bbf338de38abaebba94da28bfd28af78ea81bfa

SHA-256:
f771a00bc2901cff4239f55f847a067861a1c22a039583895b2f281def929fe6

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 8:18:34 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.VKontakteDJ
7.1.1

AhnLab V3 Security
PUP/Win32.DownloadManager
2015.09.17

Avira AntiVirus
TR/Rogue.622592.138
8.3.2.2

AVG
Downloader.MSIL
2016.0.2980

Baidu Antivirus
Hacktool.Win32.Agent
4.0.3.15920

Dr.Web
Program.VKontakteDJ.6
9.0.1.0263

Fortinet FortiGate
W32/MSIL.EFB!tr
9/20/2015

G Data
Win32.Trojan.Agent.PR4F5X
15.9.25

IKARUS anti.virus
AdWare.BundleApp
t3scan.1.9.5.0

K7 AntiVirus
Riskware
13.210.17247

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.1396

McAfee
RDN/Generic.dx
5600.6636

NANO AntiVirus
Trojan.Win32.Agent.dwrhpz
0.30.24.3283

Panda Antivirus
PUP/Multitoolbar
15.09.20.06

Quick Heal
Downloader.Agent.r3 (Not a Virus)
9.15.14.00

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D[F1]
23.00.65.15918

Sophos
Troj/MSIL-EFB
4.98

Trend Micro
TROJ_GEN.R0EBC0PHU15
10.465.20

VIPRE Antivirus
Trojan.Win32.Generic
43828

Zillya! Antivirus
Downloader.Agent.Win32.276295
2.0.0.2401

File size:
608 KB (622,592 bytes)

Product version:
1.9.0.9

Copyright:
Copyright © 2015

Original file name:
DjLoader.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\edmond ayvazyan ev arman papoyan - de asa de xosa -- armenian pop -- hf exclusive -- hd.exe

File PE Metadata
Compilation timestamp:
7/13/2015 1:18:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:w4WBtFI0U/KPnUtN7qsKQ0jnAt4BknkA3F2nhPsBtFC:/WJI0U/9rBKQ0jnpBknk62ZsJC

Entry address:
0x7619E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 70, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464.5 KB (475,648 bytes)

The file edmond ayvazyan ev arman papoyan - de asa de xosa -- armenian pop -- hf exclusive -- hd.exe has been seen being distributed by the following 50 URLs.

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=??????? ??????? - Azerbaycan marali

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=?????? ??????? ??????? - ????????? ?? ??? ??

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=Dj Shishkin vs Major Laser - Watch Out For This (Bumaye) (Dj Miltreo Mashup)

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=Gabriel Yared - Read Me To Sleep (OST The English Patient)

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=PAUL MAURIAT - ?????? ?? ?????????? ???????

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=Kim Hyun Joong (SS501) - Break Down (feat. Double K)

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=Zaman (CinaS, MizaN) - Sevgisiz Insanlar

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=????? ??????? - ???? ???? ????? (?????)

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=??????? ?????? ????????? - ????? ???? ???? ????????

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=Maryam Chemirani - Chabi Majnoun (Drama köprüsü)

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=?????? ? ?????? BASS? - ???? ?????? ?????? ? ???

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=CJ AKO ( ??? ?????) - ??? - ? ????? ????? ???????? ?????? - ??????? ?????????? ?????????? ??????? ??????? ????? ???????????? ????? ??????? ??????? 2011 ??? ???? ????????

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=Pezet - Nie musze wracac (DonDe REMIX) INSTRUMENTAL

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=????? ???????? ????????????? ????? ??? ????? ????? ?????? - ?? ? ???? ??????

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=??? ????? - ?????? ??????? ?? ??(?????)

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=????? ? ????? ????????? - ??? ?? ?????????? ? ????????, ????? ????????? ?? ??? ???????, ????? ????????? ?? ??? ????????......))

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=Tá Escrito - Grupo Revelação - As Melhores - Palco MP3

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=??????? ?????? - ?????????

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=?????? ????? - ??? ??? ????

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=????? ??? - ??????? ??? ????

http://setup.vk-dj.com/.../?advert_key=ZWMwMDAxMDBiNDAwMDI3OTAwMDAwMjdmMDAwMjdmMDAwMjdmZmFmYWNkYTliOA==&name=Lav zang - Piano

Latest 30 of 71 download URLs

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ip-static-94-242-221-153.server.lu  (94.242.221.153:80)