lz0pyia11di2.exe

MailRuSputnik

LLC Mail.Ru

The executable lz0pyia11di2.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘mailruhomesearch’. The file has been seen being downloaded from 113.171.224.177 and multiple other hosts. While running, it connects to the Internet address moscow.cdnmail.ru on port 80 using the HTTP protocol.
Publisher:
LLC Mail.Ru  (signed and verified)

Product:
MailRuSputnik

Version:
3.10.0.6

MD5:
268163a1ad7e34131a8598ffef4940e0

SHA-1:
06eb77205e4822a4369e9c7b43f4554248dd6ffa

SHA-256:
7966502d01ca7f36c0a7b220ef423f2fe6c63007c2ca0dcc55de4e7066a2ef40

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
5/10/2025 9:58:59 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
17.1.24.14

File size:
2.9 MB (3,039,448 bytes)

Product version:
3.10.0.6

Copyright:
Copyright c 2005 - 2015

Original file name:
MailRuSputnik.exe

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\users\{user}\appdata\local\temp\lz0pyia11di2.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
8/5/2015 5:00:00 PM

Valid to:
10/4/2017 4:59:59 PM

Subject:
CN=LLC Mail.Ru, O=LLC Mail.Ru, L=Moscow, S=Moscow, C=RU

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
2019877A933D8E2E71548EA4AB4827F1

File PE Metadata
Compilation timestamp:
1/19/2017 6:45:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x115E32

Entry point:
E8, 78, 03, 01, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, E9, E2, 23, 00, 00, FF, 35, 14, FD, 67, 00, FF, 15, 0C, 93, 61, 00, 85, C0, 74, 02, FF, D0, 6A, 01, 6A, 00, E8, 15, C6, 00, 00, 59, 59, E9, 2D, C6, 00, 00, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, 08, 07, 01, 00, 59, 85, C0, 74, 11, FF, 75, 08, E8, 22, 5B, 00, 00, 59, 85, C0, 74, E6, 8B, E5, 5D, C3, 6A, 01, 8D, 45, FC, C7, 45, FC, 64, B6, 61, 00, 50, 8D, 4D, F0, E8, 6B, 08, 00, 00, 68, 74, 3B, 66, 00, 8D, 45, F0, C7, 45, F0, 5C, B6, 61, 00, 50...
 
[+]

Entropy:
6.4871

Code size:
2.1 MB (2,194,432 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
mailruhomesearch

Command:
"C:\users\{user}\appdata\local\mail.ru\sputnik\ptls\mailruhomesearch.exe" --pr_deferred


The file lz0pyia11di2.exe has been seen being distributed by the following 3 URLs.

http://113.171.224.177/.../mailruhomesearch.exe

http://113.171.224.204/.../mailruhomesearch.exe

http://sputnikmailru.cdnmail.ru/mailruhomesearch.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to moscow.cdnmail.ru  (217.69.139.110:80)

TCP (HTTP):
Connects to mrds.mail.ru  (217.69.139.245:80)

TCP (HTTP):
Connects to xml.binupdate.mail.ru  (217.69.139.247:80)

TCP (HTTP):
Connects to mailru-po10.c7600.optibit.ru  (185.25.62.163:80)

TCP (HTTP):
Connects to connections.somalso.com  (185.20.186.92:80)

Remove lz0pyia11di2.exe - Powered by Reason Core Security