hamachi- torrentino.exe

Onlain Sekyuriti Sistems, OOO

The application hamachi- torrentino.exe by Onlain Sekyuriti Sistems, OOO has been detected as a potentially unwanted program by 15 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.torrentino.com.
Publisher:
Onlain Sekyuriti Sistems, OOO  (signed and verified)

MD5:
2b05181808e59bd9ead54f10ca3a07d5

SHA-1:
669e19334b325350bb932138faa0f0c095870a86

SHA-256:
e705840805d839d052356176e89ebcb2bed3259103202d387b03b42f8ba5af99

Scanner detections:
15 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 5:47:29 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Symmi.40929
1021

AVG
Win32/Heur
2015.0.3499

Bitdefender
Gen:Variant.Symmi.40929
1.0.20.550

Comodo Security
MalCrypt.Indus!
18128

Dr.Web
Trojan.LoadMoney.257
9.0.1.0110

Emsisoft Anti-Malware
Gen:Variant.Symmi.40929
8.14.04.20.08

ESET NOD32
Win32/Kryptik.BZSH.Gen
8.9698

F-Secure
Gen:Variant.Symmi.40929
11.2014-20-04_1

G Data
Gen:Variant.Symmi.40929
14.4.24

Kaspersky
not-a-virus:HEUR:Downloader.Win32.LMN
14.0.0.3988

Malwarebytes
PUP.Optional.LoadMoney.A
v2014.04.20.08

MicroWorld eScan
Gen:Variant.Symmi.40929
15.0.0.330

Qihoo 360 Security
Malware.QVM19.Gen
1.0.0.1015

Vba32 AntiVirus
BScope.Downware.LMN
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
28382

File size:
410.4 KB (420,256 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\hamachi- torrentino.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/26/2014 4:00:00 AM

Valid to:
3/27/2015 3:59:59 AM

Subject:
CN="Onlain Sekyuriti Sistems, OOO", O="Onlain Sekyuriti Sistems, OOO", STREET="12 Komn 42, ul.Vrubelya", L=Moscow, S=Moscow region, PostalCode=125080, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
38AA823949978CC988A90C3D6FDCCF0F

File PE Metadata
Compilation timestamp:
4/12/2014 6:31:17 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
31.14

CTPH (ssdeep):
6144:Pftfr0EyC6MHi4GpVsTEZfedtq3Dk8fWRP+v2lXYyj7Fr0yo/w:JdAGGpVsT8fedtof4PS2dY07FSI

Entry address:
0x2B4F

Entry point:
4B, 81, 7C, 24, FC, 48, 66, B7, DA, 1B, 4C, 24, 04, 39, 5C, 24, F8, C1, C0, 0C, 39, E3, C1, C2, 17, FD, 90, C1, D7, 0C, C1, CD, 18, C1, D6, 1A, C1, CD, 15, 87, D6, 33, 4C, 24, F4, 03, 0D, B4, A7, 42, 00, FD, F7, D7, 39, 6C, 24, F4, 89, D1, C1, E6, 00, 87, D1, C1, C5, 03, F7, D1, 8B, 44, 24, EC, C1, F8, 0D, F7, D5, 31, CD, 81, FC, BB, 93, E0, 0E, F5, FC, FD, 01, D8, 81, EB, 68, 65, 1E, 4B, 09, C2, C1, E7, 0B, C1, F8, 0F, 1B, 5C, 24, FC, C1, D5, 1B, C1, DD, 1F, F7, D6, F7, D6, 45, 39, 2D, 8B, 1C, 40, 00, 03...
 
[+]

Code size:
339.5 KB (347,648 bytes)

The file hamachi- torrentino.exe has been seen being distributed by the following URL.

Remove hamachi- torrentino.exe - Powered by Reason Core Security