undelete_360_2.14_mars_2012.exe

Undelete 360

KIRILL CHERMENIN

The application undelete_360_2.14_mars_2012.exe, “Undelete 360 - Freeware” by KIRILL CHERMENIN has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. This file is typically installed with the program UBCD4Win 3.60 by UBCD4Win Team. The file has been seen being downloaded from www.undelete360.com. While running, it connects to the Internet address hz4.chermenin.com on port 80 using the HTTP protocol.
Publisher:
File Recovery Ltd.  (signed by KIRILL CHERMENIN)

Product:
Undelete 360

Description:
Undelete 360 - Freeware

Version:
2.1.4.22

MD5:
2af108d0e818c6464ad26d6f7837cfef

SHA-1:
efd85a29fc2bd7ec12d7c44318b4f55e03e9fd97

SHA-256:
fbbeded36634340be20056121300f59315cb704355cce27eecdf976024d8df89

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/4/2024 7:55:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.KIRILLCHERMENIN.AA
14.9.8.14

File size:
2.4 MB (2,528,008 bytes)

Product version:
2.14 Build 22

Copyright:
Copyright, 2012 File Recovery Ltd.

Original file name:
undelete-360.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\undelete_360_2.14_mars_2012.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
2/17/2011 1:00:00 AM

Valid to:
2/17/2013 12:59:59 AM

Subject:
CN=KIRILL CHERMENIN, O=KIRILL CHERMENIN, STREET=70 Let Oktyabrya 17-50, L=Krasnodar, S=Krasnodarsky kray, PostalCode=350089, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
0080C6F0AF784D4CD2CE8A729FD6532512

File PE Metadata
Compilation timestamp:
3/26/2012 5:02:55 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:ypW6XKKErp0w4lUyVIjUU7CI/HQ1AgBByMsXkmAKmLla21TnFUxYJ20C:qXlMmTUr/HQKMAdXkmAn9TFKk1C

Entry address:
0x781340

Entry point:
60, BE, 00, F0, 92, 00, 8D, BE, 00, 20, AD, FF, C7, 87, 14, 4A, 57, 00, 45, 00, 2B, 6E, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.9130

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
2.3 MB (2,437,120 bytes)

The file undelete_360_2.14_mars_2012.exe has been discovered within the following program.

UBCD4Win 3.60  by UBCD4Win Team
www.ubcd4win.com
About 5% of users remove it
 
Powered by Should I Remove It?

The file undelete_360_2.14_mars_2012.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to hz4.chermenin.com  (138.201.200.72:80)

Remove undelete_360_2.14_mars_2012.exe - Powered by Reason Core Security