mediaget_id1522393ids2s.exe

Операционная система Microsoft Windows

Smart Isteit, TOV

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable mediaget_id1522393ids2s.exe, “Исполняемый файл для игры "Mahjong Titans"” has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from goo.gl.
Publisher:
Microsoft Corporation  (signed by Smart Isteit, TOV)

Product:
Операционная система Microsoft® Windows®

Description:
Исполняемый файл для игры "Mahjong Titans"

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
dcd27717ad6f54b0fcb4ae3018a830f5

SHA-1:
fceb9a5be867a35c6e54acc717eb73af19078866

SHA-256:
6e1da99cd6c2912c6199b37ed6d9b680b44a14be706f5eff54443da3b7a4f2b4

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
6/17/2019 4:10:35 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.8.4.1

File size:
5.9 MB (6,219,264 bytes)

Product version:
6.1.7600.16385

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
mahjong.exe.mui

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/21/2016 3:00:00 AM

Valid to:
5/11/2017 2:59:59 AM

Subject:
CN="Smart Isteit, TOV", OU=IT, O="Smart Isteit, TOV", STREET="Vulytsya Startova, Budynok 3", L=Misto Dnipropetrovsk, S=Dnipropetrovska, PostalCode=49041, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B4959D3231A5090CC5107015AF7B970F

File PE Metadata
Compilation timestamp:
3/28/2015 12:26:23 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
98304:iy8TVmEknFK0EuLOqLwLQwiPCdRSX8YqeGHD/ITrUat25hf4niWK5mmzwbegnVQ9:iT+Vt6qLqQwYCdg8YqeGETrFm4Voy5VJ

Entry address:
0x5D8DC8

Entry point:
6A, 70, 68, 60, 28, 9E, 00, E8, D0, 01, 00, 00, 33, DB, 53, 8B, 3D, 18, 30, 9E, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, 34, 30, 9E, 00, 59, 83, 0D, 38, 2A, 9E, 00, FF, 83, 0D, 3C, 2A...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
5.8 MB (6,133,760 bytes)

The file mediaget_id1522393ids2s.exe has been seen being distributed by the following URL.

Remove mediaget_id1522393ids2s.exe - Powered by Reason Core Security