nadopodkachatsya.exe

LLC ITC

The application nadopodkachatsya.exe by LLC ITC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
LLC ITC  (signed and verified)

MD5:
6f10415c47ea6c7bfffdff3048d0603b

SHA-1:
6b93b959f3d256e7729edfbe0ee7a26f8d71c742

SHA-256:
596b491d82698f52f60544062af17d1d716b36f227940e253d0d2f7788004e07

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/28/2024 6:49:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.30.6

File size:
520.9 KB (533,352 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\новая папка \nadopodkachatsya.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/26/2014 6:00:00 AM

Valid to:
6/27/2015 5:59:59 AM

Subject:
CN=LLC ITC, O=LLC ITC, STREET=Vvedenskogo 11/3, L=Moscow, S=Moscow oblast, PostalCode=117342, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F4DBD55156EE0DAFED4BAB130328504E

File PE Metadata
Compilation timestamp:
7/12/2014 11:22:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.15

Entry address:
0x4743

Entry point:
F7, D5, 90, D1, C9, 11, DF, F5, 90, C1, C9, 0F, 42, 87, FA, C1, E9, 1F, 81, D3, 96, A2, 42, 8E, C1, E3, 13, C1, FB, 16, 1B, 0C, 24, F7, D7, 23, 44, 24, 0C, F7, D6, 33, 3D, FA, 67, 42, 00, C1, EA, 13, 87, DF, 09, E7, 4F, C1, EF, 1F, 2B, 7C, 24, EC, C1, E2, 00, 21, CE, D1, C0, FC, 46, F7, D7, 23, 6C, 24, EC, C1, FD, 0C, 85, 15, 5F, 54, 40, 00, C1, E8, 1E, 1B, 15, 06, 9E, 43, 00, 39, EE, 33, 44, 24, 14, F5, 89, CA, 81, CD, 59, E9, 8F, 82, C1, E2, 05, F5, 1B, 74, 24, 08, C1, C7, 12, 1B, 44, 24, FC, 87, CD, C1...
 
[+]

Code size:
382.5 KB (391,680 bytes)

Remove nadopodkachatsya.exe - Powered by Reason Core Security