rld_dll_pes_2012_rar_downloader.exe

Safe Decision, Inc

The application rld_dll_pes_2012_rar_downloader.exe by Safe Decision, Inc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Safe Decision, Inc  (signed and verified)

MD5:
f1b660830e3874c97752ed645b66ca40

SHA-1:
18db20e81a3fa690a903b6807c1fab1009483a92

SHA-256:
0b857557b9efba2bff7d467732a5089a3020f65055223b57706d976cb6aa30d4

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/27/2024 1:53:58 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.EasyDownloads (M)
17.2.16.19

File size:
4.5 MB (4,718,048 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\rld_dll_pes_2012_rar_downloader.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
4/19/2010 2:00:00 AM

Valid to:
4/19/2012 1:59:59 AM

Subject:
CN="Safe Decision, Inc", O="Safe Decision, Inc", STREET=16192 Coastal Highway, L=Lewes, S=Delaware, PostalCode=19958, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
6DC4F2ADB6C01EB5AFC087B875031CE2

File PE Metadata
Compilation timestamp:
10/27/2011 5:40:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x6F03BC

Entry point:
68, 23, 7F, A8, 8D, E8, 14, 4D, 1D, 00, 8D, 64, 24, 24, 0F, 82, 46, D5, FF, FF, 66, 3D, 05, 7C, 3B, 04, 24, E9, EB, DF, FF, FF, 29, C9, 68, A1, E6, 08, 84, 8D, 64, 24, 0C, E8, 40, AB, 00, 00, E9, 95, 40, D7, FF, 68, E4, 83, BC, 8D, E8, 64, 45, 1D, 00, 86, 68, 10, 85, BC, 8D, E8, 20, 5B, 1D, 00, E0, 60, 5A, 0B, E9, 5A, F3, FF, FF, AF, 7D, 1F, F2, B8, 62, E6, B3, 79, FA, C0, 6B, 35, F3, B9, 71, 32, D0, 46, 8D, 99, C1, 28, 6B, BF, 1D, 65, 55, D3, 7C, 12, 28, 87, B8, 34, F1, 48, 2B, 68, 1E, 8D, 6E, F7, 98, 63...
 
[+]

Code size:
8.8 MB (9,199,616 bytes)

Remove rld_dll_pes_2012_rar_downloader.exe - Powered by Reason Core Security