rambler_silent2.exe

7-Zip

Digital Pine, LLC

The application rambler_silent2.exe, “7z Setup SFX small” by Digital Pine has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the 7z Setup installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from fastloadmedia.ru and multiple other hosts.
Publisher:
Igor Pavlov  (signed by Digital Pine, LLC)

Product:
7-Zip

Description:
7z Setup SFX small

Version:
9.20

MD5:
4dfb91e2a313ee7e1fda8c3e1969767c

SHA-1:
88a3751d79dbeb244af25cd9c3fded6be6870d12

SHA-256:
6f13191dc022b3f50e9db372f4ff411f1e0e96bc5ff4b19362bf246291ca7093

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/23/2024 7:15:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.DigitalPine.P
14.7.29.12

File size:
562.6 KB (576,056 bytes)

Product version:
9.20

Copyright:
Copyright (c) 1999-2010 Igor Pavlov

Original file name:
7zS2.sfx.exe

File type:
Executable application (Win32 EXE)

Installer:
7z Setup

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\rambler_silent2.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
6/17/2013 3:00:00 AM

Valid to:
3/30/2016 3:00:00 PM

Subject:
CN="Digital Pine, LLC", O="Digital Pine, LLC", L=Moscow, C=RU

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0C6DFC094A13DA127C9280621A006F48

File PE Metadata
Compilation timestamp:
11/18/2010 8:41:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:MiaUenuaGK6Jm1O4tpjsxasdtpykmXSI3seCs9w65No0Dyp5bKdpSWksd91PLA:5aUyGVT40fAkmXSAsoq63RpSl0TA

Entry address:
0x643F

Entry point:
55, 8B, EC, 6A, FF, 68, E8, 70, 40, 00, 68, C0, 65, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 6C, 70, 40, 00, 59, 83, 0D, 00, A2, 40, 00, FF, 83, 0D, 04, A2, 40, 00, FF, FF, 15, 70, 70, 40, 00, 8B, 0D, F0, 81, 40, 00, 89, 08, FF, 15, 74, 70, 40, 00, 8B, 0D, EC, 81, 40, 00, 89, 08, A1, 78, 70, 40, 00, 8B, 00, A3, 08, A2, 40, 00, E8, 11, 01, 00, 00, 39, 1D, D0, 81, 40, 00, 75, 0C, 68, BC, 65, 40, 00, FF, 15, 7C, 70...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
21.5 KB (22,016 bytes)

The file rambler_silent2.exe has been seen being distributed by the following 2 URLs.

Remove rambler_silent2.exe - Powered by Reason Core Security