t01zf0o.exe

Boris Vladimirovich BOBOVSKY

The setup package is an adware installer (using InstalleRex) that will deploy with little or no user consent adware offerings including but not limited to browser extensions (add-ins, toolbars) that will inject various forms of advertising in the user's browser. The application t01zf0o.exe by Boris Vladimirovich BOBOVSKY has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from fastwinnermyall.ru. While running, it connects to the Internet address dl.softservers.net on port 80 using the HTTP protocol.
Publisher:
Boris Vladimirovich BOBOVSKY  (signed and verified)

MD5:
4b1a5b899b66e7fb4d193aead34ba9a2

SHA-1:
29ef8e42ad12ac46f40008fe35e318f30a2109ed

SHA-256:
590a38f458347fa9e7ae23f762ee4ac6ac4b1f57f3a16fe4dd1ecb4da37b7256

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles additional adware products (monetized browser extensions, ad injectors) in the installer.

Analysis date:
4/19/2024 4:03:02 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick.BorisVladimirovichBOBOVSKY (M)
16.2.10.6

File size:
1.3 MB (1,328,080 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\t01zf0o.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
12/27/2013 3:31:44 AM

Valid to:
12/27/2014 3:31:44 AM

Subject:
E=bob@borr.info, CN="Open Source Developer, Boris Vladimirovich BOBOVSKY", O=Boris Vladimirovich BOBOVSKY, C=UA

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
1ADBC4E5D3604FB9725702528437E82A

File PE Metadata
Compilation timestamp:
9/9/2013 12:07:55 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:OLzrCO1hUAf2v59eaVUb3iP1t3HhYgsZoJkw/sYFze:OLK4/f2v5kaVUb3ijhdsZPBYde

Entry address:
0xD5B4

Entry point:
E8, 72, 4F, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 38, C0, 41, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 3C, C0, 41, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, 09, 19, 00, 00, 85, C0, 75, 06, B8, A0, C1, 41, 00, C3, 83, C0, 08, C3, E8, F6, 18, 00, 00, 85, C0, 75, 06, B8, A4, C1, 41, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Code size:
88 KB (90,112 bytes)

The file t01zf0o.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to i1.stylefun.info  (198.7.61.118:80)

TCP (HTTP):
Connects to dl.softservers.net  (184.154.145.171:80)

TCP (HTTP):
Connects to c1.getapplicationmy.info  (54.201.215.30:80)

Remove t01zf0o.exe - Powered by Reason Core Security