rencontreshard.exe

Rencontres Hard

Rentabiliweb Belgique

The application rencontreshard.exe by Rentabiliweb Belgique has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from download.rencontreshard.com.
Publisher:
Rentabiliweb  (signed by Rentabiliweb Belgique)

Product:
Rencontres Hard

Version:
1.0.0.4

MD5:
3199b07128fbad82da4a797c7a563d5d

SHA-1:
39e1cfcd31fe7c63d07e4be02c41d1cd79a24a61

SHA-256:
bd97b5c5bfa0ad1647034c409abb7fda0b9d78eb5413b7d8fcf19a8da1cb0cbc

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 1:42:55 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Virut.Gen
7.11.30.172

Dr.Web
Trojan.DownLoader10.14711
9.0.1.025

F-Secure
Riskware.Application.Bundler.AA
11.2016-25-01_2

Reason Heuristics
Optional.Rentabiliweb.Messanger.Installer.Meta (L)
16.1.25.1

Trend Micro House Call
HV_ZYX_BK083B4D.TOMC
7.2.25

File size:
135.1 KB (138,352 bytes)

Copyright:
Rentabiliweb

Trademarks:
Rencontres Hard is a trademark of Rentabiliweb company

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/8/2012 2:00:00 AM

Valid to:
10/20/2014 1:59:59 AM

Subject:
CN=Rentabiliweb Belgique, OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Rentabiliweb Belgique, L=Bruxelles, S=Saint-Gilles, C=BE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2CBF12B6DDCA81E1319702E79282058A

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:hQpQ5EP0ijnRTXJxCizhSVddPWkFEg5hwQE674HZIKNJrGZuWZL6:hQIURTXJcchSVzPdvDwQt74HJreG

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file rencontreshard.exe has been seen being distributed by the following URL.

Remove rencontreshard.exe - Powered by Reason Core Security