park gorkogo - moscow calling iz filma fizruk iplayer fm.exe

Acko.net colormap

IT River

The application park gorkogo - moscow calling iz filma fizruk iplayer fm.exe by IT River has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Acko.net  (signed by IT River)

Product:
Acko.net colormap

Description:
Colormap APE

Version:
1, 3, 0, 0

MD5:
b3b55cfb904b9297da99fb51c3eb51ca

SHA-1:
44de2c0435d7bb3393e7f079d70f29186318263f

SHA-256:
ae7cceb89b08c9e3c6edfff0ce9f6e54d6f7ce53e857b295e20510603b3bbad3

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/27/2024 2:58:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ITRiver (M)
16.2.14.2

File size:
477.4 KB (488,808 bytes)

Product version:
1, 3, 0, 0

Copyright:
Copyright © 2003

Original file name:
colormap.ape

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\park gorkogo - moscow calling iz filma fizruk iplayer fm.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/25/2014 3:00:00 AM

Valid to:
2/26/2015 2:59:59 AM

Subject:
CN=IT River, O=IT River, STREET="Obolenskiy, 9", L=Moscow, S=Moscow oblast, PostalCode=119021, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0F02E0C593A3B9A15B22F5853C90D66B

File PE Metadata
Compilation timestamp:
6/20/1992 2:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:PciduSMVYEZNE0RXyIXrUJ3kw7yQ/ArbMa:PiZYE3E0RXRrUp7Doca

Entry address:
0x16A4

Entry point:
83, 3D, 47, B0, 46, 00, 01, 75, 22, 8B, 0D, 47, B0, 46, 00, 8B, 05, 32, B0, 46, 00, 89, 0D, 27, B0, 46, 00, 89, 05, 51, B0, 46, 00, C7, 05, 20, B0, 46, 00, 9A, 1B, 01, 00, 0F, 85, 1F, 00, 00, 00, 89, 15, A0, B0, 46, 00, 87, 0D, 7C, B0, 46, 00, 89, 05, 02, B1, 46, 00, 89, 35, D6, B0, 46, 00, 89, 15, 7A, B0, 46, 00, C3, 68, 7C, 10, 40, 00, FF, 05, 35, B0, 46, 00, 89, 15, 8C, B0, 46, 00, 89, 05, B2, B0, 46, 00, BB, 29, 00, 00, 00, 21, 05, CB, B0, 46, 00, C7, 05, 24, B0, 46, 00, 5C, 11, 40, 00, B0, 01, C3, 90...
 
[+]

Code size:
421 KB (431,104 bytes)