phantomers_install_87072723-at4zekxx.exe

QGNA

Syncopate LLC

The application phantomers_install_87072723-at4zekxx.exe, “QGNA Setup ” by Syncopate has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from fs0.gamenet.ru.
Publisher:
Global Gamers Solutions Ltd. ©   (signed by Syncopate LLC)

Product:
QGNA

Description:
QGNA Setup

Version:
1.0.62.0

MD5:
33e404703c9deea5ca8ea22ac6637292

SHA-1:
c43a1f1d3e2cf3d4d3b1dbd366f7c95d5e1cf357

SHA-256:
55712c1b13ee7a89b1d07cf3e6f1779291cb0f939b28a49ced14d98fcd495455

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/28/2024 9:20:24 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Syncopate.Installer (M)
16.3.5.3

File size:
69.1 MB (72,507,568 bytes)

Product version:
3.7.18.1969

Copyright:
Global Gamers Solutions Ltd. ©

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\phantomers_install_87072723-at4zekxx.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
9/24/2015 10:00:00 AM

Valid to:
12/24/2017 9:59:59 AM

Subject:
CN=Syncopate LLC, O=Syncopate LLC, L=Moscow, S=Moscow, C=RU

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
7E12573328ADF45B6F3EC341E646293A

File PE Metadata
Compilation timestamp:
10/9/2012 6:48:22 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
1572864:PQ7p3Ev3QBOSRF7kqZQM8igmG6/EUiGrbds7Vv8FYk8CE:oVEv3RSUmv8lfSE3GHuZv8OJ

Entry address:
0xF3BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 64, ED, 40, 00, E8, E8, 71, FF, FF, 33, C0, 55, 68, 89, FA, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 45, FA, 40, 00, 64, FF, 32, 64, 89, 22, A1, 48, 3B, 41, 00, E8, BE, F7, FF, FF, E8, 65, F3, FF, FF, 8D, 55, EC, 33, C0, E8, F7, C3, FF, FF, 8B, 55, EC, B8, 4C, 66, 41, 00, E8, 6A, 58, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 4C, 66, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
59 KB (60,416 bytes)

The file phantomers_install_87072723-at4zekxx.exe has been seen being distributed by the following URL.

Remove phantomers_install_87072723-at4zekxx.exe - Powered by Reason Core Security