VKMusicSetup.exe

VKMusicPlayer

LLC Pentagon

The application VKMusicSetup.exe by LLC Pentagon has been detected as a potentially unwanted program by 15 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from vkmusic.ru.
Publisher:
LLC Pentagon  (signed and verified)

Product:
VKMusicPlayer

Version:
1.0.5353.18304

MD5:
5f2fc894ad67d692973b0629d5ed3295

SHA-1:
fa999c93098a61ae7a1d7c854b6c8475bbf61e86

SHA-256:
c5685cbcdc6ba7aeab0c7a41157101cc5cd8e95a0d28a54dd7f67314bdf4e735

Scanner detections:
15 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 9:50:27 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1832955
804

Baidu Antivirus
PUA.MSIL.VKPentago
4.0.3.141122

Bitdefender
Trojan.GenericKD.1832955
1.0.20.1630

Dr.Web
Adware.Downware.5217
9.0.1.0326

Emsisoft Anti-Malware
Trojan.GenericKD.1832955
8.14.11.22.01

ESET NOD32
MSIL/VKPentago (variant)
8.10765

F-Secure
Trojan.GenericKD.1832955
11.2014-22-11_7

G Data
Trojan.GenericKD.1832955
14.11.24

IKARUS anti.virus
PUA.MSIL.VKPentago
t3scan.1.8.3.0

K7 AntiVirus
Trojan
13.185.14098

McAfee
Artemis!5F2FC894AD67
5600.6938

nProtect
Trojan.GenericKD.1832955
14.11.21.01

Reason Heuristics
PUP.Installer.Pentagon.M
14.11.22.13

Sophos
Generic PUA EL
4.98

Trend Micro House Call
TROJ_GEN.R02SH05JR14
7.2.326

File size:
3 MB (3,113,488 bytes)

Product version:
1.0.5353.18304

Copyright:
Copyright (c) LLC Pentagon. All rights reserved.

Original file name:
VKMusicSetup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\vkmusicsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/15/2014 3:00:00 AM

Valid to:
4/10/2015 2:59:59 AM

Subject:
CN=LLC Pentagon, O=LLC Pentagon, L=Chelyabinsk, S=Chelyabinsk oblast, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6953C3B39EC862D3EEFA6D7971B66B07

File PE Metadata
Compilation timestamp:
11/28/2013 4:14:28 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:hB4XTlGy/zEg2M74ryRqqRGzQc4QgBux9Q21iScH2mm5IlXmJ:hq0izEtM7iyRqLgBuViSKTmWmJ

Entry address:
0x267A5

Entry point:
E8, C9, 39, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, D0, 60, 45, 00, 75, 02, F3, C3, E9, C4, 40, 00, 00, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 7F, 0F, B6, 44, 24, 08, 0F, BA, 25, 44, 7C, 45, 00, 01, 73, 0D, 8B, 4C, 24, 0C, 57, 8B, 7C, 24, 08, F3, AA, EB, 5D, 8B, 54, 24, 0C, 81, FA, 80, 00, 00, 00, 7C, 0E, 0F, BA, 25, 80, 61, 45, 00, 01, 0F, 82, 79, 41, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B...
 
[+]

Code size:
229.5 KB (235,008 bytes)

The file VKMusicSetup.exe has been seen being distributed by the following URL.

Remove VKMusicSetup.exe - Powered by Reason Core Security