magic mike xxl 2015 hdrip xvid ac3 etrg.exe

SInstall

JELBRUS LLC

The application magic mike xxl 2015 hdrip xvid ac3 etrg.exe by JELBRUS has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from downloadfast.me.
Publisher:
Super Installer  (signed by JELBRUS LLC)

Product:
SInstall

Description:
Super Installer

Version:
1,4,0,3

MD5:
89efcb73a17c00201d0f35711eb64240

SHA-1:
d226bae59a8f010bec7ac07d35d77d38f7f9d4bb

SHA-256:
78014ac1e9d6c5bd8f450b09f7878b3547993ae5ae88bde95c75526c23dfc159

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/4/2024 2:26:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Techsnab.JELBRUS.Installer (M)
16.1.19.5

File size:
666.5 KB (682,536 bytes)

Product version:
1,4,0,3

Copyright:
Copyright 2015 Super Installer, All rights reserved.

Original file name:
SISoft.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\magic mike xxl 2015 hdrip xvid ac3 etrg.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
8/25/2015 6:00:00 PM

Valid to:
8/25/2017 5:59:59 PM

Subject:
CN=JELBRUS LLC, O=JELBRUS LLC, L=Moscow, S=Moscow, C=RU

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
28CAAD3561DCD1CD6D7D2F23E2AC6FD7

File PE Metadata
Compilation timestamp:
9/4/2015 5:47:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:6atOK91Vc6ez+ge5trBmK1mp7byqsPrcnHzHDNWcIgtWJRCukPN+A03Mg1ZBY04k:6atOK91Vcr+wo40F9smVcZ46MOA9hD

Entry address:
0x7B1DB

Entry point:
E8, 6C, 7A, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 40, 24, 49, 00, E8, CF, 4A, 00, 00, E8, 18, 44, 00, 00, 0F, B7, F0, 6A, 02, E8, FF, 79, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, EE, 3C, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.4197

Code size:
554 KB (567,296 bytes)

The file magic mike xxl 2015 hdrip xvid ac3 etrg.exe has been seen being distributed by the following URL.

Remove magic mike xxl 2015 hdrip xvid ac3 etrg.exe - Powered by Reason Core Security