LBP2900ru.exe

Media Labs Ltd

The application LBP2900ru.exe by Media Labs has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from ticnofiledownloader.com.
Publisher:
Media Labs Ltd  (signed and verified)

Version:
0.3.19.103

MD5:
25588e5b67db49a971dc37bb9fbba3e7

SHA-1:
c6ab64933a5c3b8afd5c132cb7fc38d7db8feb38

SHA-256:
7197a12c9ed63058dd532203df53ac1366b3495038968090bd58d0e0af402417

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 9:17:20 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Crypt.XPACK.Gen2
7.11.145.44

AVG
MalSign.Media Labs Ltd
2015.0.3494

Dr.Web
Adware.Downware.3018
9.0.1.0114

ESET NOD32
Win32/Packed.PrivateEXEProtector (variant)
8.9720

IKARUS anti.virus
Trojan.Win32.Llac
t3scan.1.6.1.0

Norman
Agent.BA
11.20140424

Rising Antivirus
PE:Malware.Packed!1.9C4E
23.00.65.14422

Sophos
Media Labs
4.98

File size:
1.1 MB (1,205,704 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\users\{user}\downloads\lbp2900ru.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/13/2013 8:00:00 PM

Valid to:
6/14/2014 7:59:59 PM

Subject:
CN=Media Labs Ltd, O=Media Labs Ltd, STREET="Electrolitnii pr., 1-3", L=Moscow, S=Moscow, PostalCode=115230, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5D826AF104D695AF42BF589E71B12A07

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:uDC8qXgJQ+TouDDRS/psCY2DLzJqUy70hOiQfTPPY+PbaR:uDpTloN/psd2DJBMyOiX8W

Entry address:
0x1000

Entry point:
68, 85, 40, EE, 65, 64, FF, 35, 00, 00, 00, 00, 9C, 89, 04, 24, 9C, 89, 1C, 24, 51, 9C, 89, 14, 24, 56, 9C, 89, 3C, 24, 55, 68, C1, 10, 40, 00, 8F, 05, C9, 24, AF, 0B, FF, 15, C9, 24, AF, 0B, C3, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 6A, 01, 1D, 47, 48, E9, B5, 35, D6, 33, 9B, CB, 35, B6, 0B, E7, D1, DD, 1F, 3E, C1, 8C, 73, 27, 22, 31, 40, F0, 46, DF, EE, 70, C5, C8, 48, 84, B2, 77, A3, CE, 88, 9C, D0, E5, 92, 5F, 9D, A1, EB, 73, 26, 63, 52, 6A, 60, 72, 5B, F9, 84, C6, E2, 47, 4C...
 
[+]

Entropy:
7.8614  (probably packed)

Code size:
699 KB (715,776 bytes)

The file LBP2900ru.exe has been seen being distributed by the following URL.

Remove LBP2900ru.exe - Powered by Reason Core Security