met art 14 09 29 nichole a besige xxx imageset p4l.exe

WInstall

JELBRUS LLC

The application met art 14 09 29 nichole a besige xxx imageset p4l.exe by JELBRUS has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from 838e1efc6afbf2457cfa-8e8f96cf28c06f52378ac5215fddd99f.r7.cf1.rackcdn.com.
Publisher:
Wish Installer  (signed by JELBRUS LLC)

Product:
WInstall

Description:
Wish Installer

Version:
1,4,1,0

MD5:
ab5f257a9c5b4fde73e1c6fc77963d0c

SHA-1:
e7de129b0c16bd74d92f57f60dfa2ad6fb333e91

SHA-256:
100ca5df4b2e189494358b0b08fa12f95015ffc9033c29e9e1d343678a38afa2

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/18/2024 10:58:48 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Techsnab.JELBRUS.Installer (M)
16.6.26.18

File size:
641 KB (656,424 bytes)

Product version:
1,4,1,0

Copyright:
Copyright 2015 Wish Installer, All rights reserved.

Original file name:
WISoft.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\met art 14 09 29 nichole a besige xxx imageset p4l.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
8/26/2015 2:00:00 AM

Valid to:
8/26/2017 1:59:59 AM

Subject:
CN=JELBRUS LLC, O=JELBRUS LLC, L=Moscow, S=Moscow, C=RU

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
28CAAD3561DCD1CD6D7D2F23E2AC6FD7

File PE Metadata
Compilation timestamp:
9/7/2015 5:15:38 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:S9bxt1iFnEa7Tzsqq+AB4+aU5yjxO4OLt5yF/Cd7VOifyVRfY2WGuEHXwypDbwqn:Sjt1iJl7TzsX+vHfUcVS5noZ46MOpFb5

Entry address:
0x7501D

Entry point:
E8, 6A, 7A, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 40, C4, 48, 00, E8, CD, 4A, 00, 00, E8, 16, 44, 00, 00, 0F, B7, F0, 6A, 02, E8, FD, 79, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, EC, 3C, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
529.5 KB (542,208 bytes)

The file met art 14 09 29 nichole a besige xxx imageset p4l.exe has been seen being distributed by the following URL.