installerdu-2.4.2.9633.exe

Carambis Installer

ROSTPEI LTD

The application installerdu-2.4.2.9633.exe by ROSTPEI has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from www.carambis.ru. While running, it connects to the Internet address server6.ext.freeteam.org on port 80 using the HTTP protocol.
Publisher:
Carambis (ROSTPAY LTD.)  (signed by ROSTPEI LTD)

Product:
Carambis Installer

Version:
1.0.0.2

MD5:
bc642d16ff727b47604d70ff305f08de

SHA-1:
33913bff60d59ef2536f3f3d21f4d04ef8e15c34

SHA-256:
a65001b94786f8a32220005d3b8813dafaf03160d2758b6934a4bd352a2e962d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
7/17/2018 5:11:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.MediaFrog (M)
16.12.8.20

File size:
919.7 KB (941,784 bytes)

Product version:
1.0.0.2

Copyright:
Carambis (ROSTPAY LTD.) All rights reserved. 2014

Original file name:
Carambis Installer

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\installerdu-2.4.2.9633.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/26/2016 3:00:00 AM

Valid to:
8/27/2019 2:59:59 AM

Subject:
CN=ROSTPEI LTD, O=ROSTPEI LTD, STREET="str. Dolomanovsky, 70D, office 1001", L=Rostov-on-Don, S=Rostov region, PostalCode=344011, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
57F3D607DA7727B586CD4AFC0D5D8D37

File PE Metadata
Compilation timestamp:
12/8/2016 11:07:19 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x2BD520

Entry point:
60, BE, 00, D0, 5D, 00, 8D, BE, 00, 40, E2, FF, C7, 87, 34, 61, 27, 00, 72, 61, AC, 03, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 25, B8, 2B, 00, 57, 83, C3, 04, 53, 68, 1E, 05, 0E, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9...
 
[+]

Code size:
904 KB (925,696 bytes)

The file installerdu-2.4.2.9633.exe has been seen being distributed by the following URL.

https://www.carambis.ru/programs/.../download.html?cs_aff=drbt99

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to server6.ext.freeteam.org  (46.46.160.233:80)

Remove installerdu-2.4.2.9633.exe - Powered by Reason Core Security