ernest-heminguei.-sobranie-sochinenii-v-4-tomah-komplekt_15518231_218.exe

Monkeke Inc.

The application ernest-heminguei.-sobranie-sochinenii-v-4-tomah-komplekt_15518231_218.exe by Monkeke has been detected as a potentially unwanted program by 4 anti-malware scanners.
Publisher:
Monkeke Inc.  (signed and verified)

MD5:
a1a16541734bb51a374f9010b9fded01

SHA-1:
efea9a6cada72889373cff3cb517c5067bbab6d2

SHA-256:
5f4de51865c60c4bbb6ed9e9ccff35dd2c8c91f2acbe6a3e3478bbfd3a63cb62

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 7:14:50 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
BackDoor.Evit.27
9.0.1.068

ESET NOD32
Win32/Adware.Toolbar.Webalta.BT
11.7955

Kaspersky
not-a-virus:HEUR:Downloader.Win32.Walta
14.0.0.-1283

Trend Micro House Call
TROJ_GEN.F47V0131
7.2.68

File size:
1.5 MB (1,522,992 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ernest-heminguei.-sobranie-sochinenii-v-4-tomah-komplekt_15518231_218.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
2/1/2012 8:51:32 PM

Valid to:
2/1/2013 8:51:32 PM

Subject:
CN=Monkeke Inc., O=Monkeke Inc., L=Flemington, S=MO, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0453F0B8F59ABD

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x90EC4

Entry point:
55, 8B, EC, 83, C4, F0, B8, EC, 0B, 49, 00, E8, 4C, 59, F7, FF, A1, 98, 2C, 49, 00, 8B, 00, E8, 84, 94, FC, FF, 8B, 0D, D0, 2D, 49, 00, A1, 98, 2C, 49, 00, 8B, 00, 8B, 15, FC, F9, 46, 00, E8, 84, 94, FC, FF, 8B, 0D, 0C, 2E, 49, 00, A1, 98, 2C, 49, 00, 8B, 00, 8B, 15, A4, F7, 46, 00, E8, 6C, 94, FC, FF, 8B, 0D, 4C, 2C, 49, 00, A1, 98, 2C, 49, 00, 8B, 00, 8B, 15, 00, 0A, 49, 00, E8, 54, 94, FC, FF, A1, 98, 2C, 49, 00, 8B, 00, E8, C8, 94, FC, FF, E8, A7, 33, F7, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
576 KB (589,824 bytes)