pro_evolution_soccer_2014-reloaded.exe

Installer

TAIMED LLC

The application pro_evolution_soccer_2014-reloaded.exe by TAIMED has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from amazingexperience.net. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
TAIMED LLC  (signed and verified)

Product:
Installer

Description:
Taimed

Version:
1.1.1.0

MD5:
f933cc1b84c3134dbbacbfe3b8f76ff3

SHA-1:
71136d92b5aa1821de626507a82af95a10e49791

SHA-256:
9cbf3c3d8f1a65ca79b73a905a419004a45e15a2d14641f794a936a4ffd37520

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 8:54:29 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.12.15

File size:
217.3 KB (222,480 bytes)

Product version:
1.1.1.0

Copyright:
Copyright 2015 TAIMED, All rights reserved.

Original file name:
instj.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\pro_evolution_soccer_2014-reloaded.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/11/2014 12:00:00 AM

Valid to:
6/10/2017 11:59:59 PM

Subject:
CN=TAIMED LLC, O=TAIMED LLC, STREET=Kirova st. 20A office 422, L=Moscow district, S=Lubertsy, PostalCode=140005, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00DC809665388D66359464C754C696D5C6

File PE Metadata
Compilation timestamp:
4/6/2015 9:21:18 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x12A5A

Entry point:
E8, A6, 77, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, A0, A3, 42, 00, E8, A0, 48, 00, 00, E8, 77, 79, 00, 00, 0F, B7, F0, 6A, 02, E8, 39, 77, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, D7, 44, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
136.5 KB (139,776 bytes)

The file pro_evolution_soccer_2014-reloaded.exe has been seen being distributed by the following URL.

http://amazingexperience.net/index.php?v=GGsLZdlzw6ZPktEX&channel=pbbt&fln=UHJvX0V2b2x1dGlvbl9Tb2NjZXJfMjAxNC1SRUxPQURFRA==&t=1428587301&rnd=

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove pro_evolution_soccer_2014-reloaded.exe - Powered by Reason Core Security