meridian new world eng l.exe

Onlain Sekyuriti Sistems, OOO

The application meridian new world eng l.exe by Onlain Sekyuriti Sistems, OOO has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from forces.gor-enters.ru.
Publisher:
Onlain Sekyuriti Sistems, OOO  (signed and verified)

MD5:
07d838f54a23519ec80b9e75f1841d10

SHA-1:
fa841a26cda0fa596960e38aad1da47c22c79330

SHA-256:
44659695c82c05466b7490b6f93393b6d30bb7dcc5368ee60eef3d3cdba88696

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 11:28:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OnlainSekyuritiSistems (M)
15.10.11.16

File size:
376.4 KB (385,440 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\meridian new world eng l.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/26/2014 2:00:00 AM

Valid to:
3/27/2015 1:59:59 AM

Subject:
CN="Onlain Sekyuriti Sistems, OOO", O="Onlain Sekyuriti Sistems, OOO", STREET="12 Komn 42, ul.Vrubelya", L=Moscow, S=Moscow region, PostalCode=125080, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
38AA823949978CC988A90C3D6FDCCF0F

File PE Metadata
Compilation timestamp:
4/6/2014 8:32:10 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:ivYgJ3xHsYmCo6S1CnWcsW948ISQlN84GpLWr9jWupO92cY6M5:WB1pS4Wc1jRQlN8IWx9JvM5

Entry address:
0x3F7E

Entry point:
90, C1, E8, 1F, C1, E9, 0C, 42, C1, D0, 18, 4F, 19, ED, 13, 6C, 24, 08, 4F, C1, E1, 0D, F5, FD, 1B, 3C, 24, 39, 6C, 24, F8, BD, 30, 71, EE, 42, FD, C1, D7, 08, 42, 81, C5, 54, D0, 51, BD, C1, D8, 07, B8, 39, 22, FA, C8, 09, F8, C1, E1, 11, 4D, 87, CA, C1, D6, 07, C1, F9, 13, 45, F5, FD, 0F, B6, 4D, 00, 87, FF, 96, 81, C1, 88, EB, 1E, D4, 4A, C1, E0, 1B, 81, C1, FC, 54, 21, 2C, F7, 44, 24, EC, A8, CD, A6, 51, 96, 8A, 19, 2B, 74, 24, F8, 23, 7C, 24, F8, 33, 14, 24, 23, 44, 24, F8, 88, 5D, 00, 87, CE, 21, E2...
 
[+]

Code size:
352 KB (360,448 bytes)

The file meridian new world eng l.exe has been seen being distributed by the following URL.

Remove meridian new world eng l.exe - Powered by Reason Core Security