kickasstorrent.com_10924_i129611388_il345.exe

AITI Strim CONSULTING, TOV

The application kickasstorrent.com_10924_i129611388_il345.exe by AITI Strim CONSULTING, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
AITI Strim CONSULTING, TOV  (signed and verified)

MD5:
90ed0f29b99aa9ec560e5bdc931debb9

SHA-1:
813c1b3ade7e307964ab7b66cc5621d9365d82bc

SHA-256:
e37d5552c84b17c2cc1151b343fb61ffd62ccc74a265959b7d2bfab2a4d68523

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 4:27:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize
17.2.22.5

File size:
2 MB (2,069,320 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\kickasstorrent.com_10924_i129611388_il345.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/11/2016 3:00:00 AM

Valid to:
1/11/2017 2:59:59 AM

Subject:
CN="AITI Strim CONSULTING, TOV", OU=IT, O="AITI Strim CONSULTING, TOV", STREET="Bud. 53-55, vul.Pochainynska", L=Kyyiv, S=Kyyiv, PostalCode=04080, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5A7A1CB365BD8EA3567456D3B8166630

File PE Metadata
Compilation timestamp:
1/25/2016 11:32:52 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x29DE8A

Entry point:
68, 84, 3F, D5, E7, E8, 4D, DB, FE, FF, 54, 44, 21, EB, 62, 6F, 40, 74, 58, 35, DA, 31, ED, 34, 55, 4F, 37, E9, 55, 73, 63, 6F, 54, 36, E2, 3B, FC, 55, 31, CB, 3D, DA, 0B, 5C, 4E, 23, E0, 4A, 63, 72, 69, 50, 29, D7, 03, 9F, 57, 44, 36, C7, 73, 78, 62, 7E, 5F, 2F, FE, 26, F0, 57, 38, DD, 3D, 8D, 0F, 85, FA, DC, 0A, 00, 80, 7C, 08, 08, 73, E9, EA, DC, 0A, 00, 43, 62, 4E, C4, 30, 88, F6, 10, 7F, 21, 26, 42, 30, 84, 6F, 08, 59, 10, 32, 20, DD, 40, 74, 81, FE, 02, 44, 05, 2D, 0A, C2, 14, 27, 29, EE, 52, 6A, A5...
 
[+]

Entropy:
7.9869  (probably packed)

Code size:
2 MB (2,058,752 bytes)