tanki online hack_10924_i129739813_il345.exe

AITI Strim CONSULTING, TOV

The application tanki online hack_10924_i129739813_il345.exe by AITI Strim CONSULTING, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
AITI Strim CONSULTING, TOV  (signed and verified)

MD5:
cf9f2df41a77746eb639e9f22448e639

SHA-1:
8fff97cd4c8cf10c8bf2785cff2e6e9cddce67fe

SHA-256:
e38eabe89918b1c4d56d3a997c08c18b867f6fc4d19f5d02ce2046728db6c1a8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 4:09:22 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize.AITIStri (M)
16.6.8.1

File size:
2.1 MB (2,167,848 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\aff540dc.unpacker_v7353qx4kg3sa!app\tanki+online+hack.zip\tanki online hack_10924_i129739813_il345.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/11/2016 1:00:00 AM

Valid to:
1/11/2017 12:59:59 AM

Subject:
CN="AITI Strim CONSULTING, TOV", OU=IT, O="AITI Strim CONSULTING, TOV", STREET="Bud. 53-55, vul.Pochainynska", L=Kyyiv, S=Kyyiv, PostalCode=04080, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5A7A1CB365BD8EA3567456D3B8166630

File PE Metadata
Compilation timestamp:
1/26/2016 4:52:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:AbXGznGgIS5o6NVBnUW4Q6cveN0DV8tEDb1mvR:kGznE2osVBnUW4Q6cvJV8tEDBKR

Entry address:
0x49F310

Entry point:
68, AB, B9, F2, 47, E8, F0, 56, E0, FF, 0F, 85, DB, AF, E5, FF, 5E, 66, C1, DF, E1, 5B, 87, FF, F5, 2B, C0, 5F, E9, 37, 68, E0, FF, 04, D2, 6F, 22, F5, 5B, 79, 67, 4D, 2C, 1A, A5, DB, 0B, E3, 47, 22, F1, 6D, 5E, 70, 49, 23, 0D, 9A, B4, DE, 28, D9, 0E, CA, A7, FC, 29, 3C, EC, C0, 85, 29, 12, 82, 5B, 26, E1, 8A, CB, 32, 5C, C0, 35, 17, 46, 9C, 09, 17, B2, 40, 8E, E2, AA, 66, C5, F9, D2, 98, C3, AF, B7, 03, EB, E6, 49, 2A, 30, 00, 2F, EC, 41, F3, C7, F3, FD, EB, D4, 0D, 6E, B8, BE, 00, 4E, D6, 85, 21, E3, DE...
 
[+]

Code size:
2 MB (2,148,352 bytes)

Remove tanki online hack_10924_i129739813_il345.exe - Powered by Reason Core Security