ZaycevNetSetup.exe

Zaycev.net официальное приложение

LLC Pentagon

The application ZaycevNetSetup.exe by LLC Pentagon has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from browserinstall.zaycev.net. While running, it connects to the Internet address front.portal.rambler.ru on port 443.
Publisher:
ZAYCEV MEDIA GROUP LTD  (signed by LLC Pentagon)

Product:
Zaycev.net официальное приложение

Version:
1.0.5251.24719

MD5:
1c74c6d61a0f784ef2d2630a291965df

SHA-1:
818f52d82fe7c9b0c76cfe7bdc07620d29227553

SHA-256:
8723ce810f013ee2409d5f70cb0dc85988860f47ba80da88e1df95121479dd8d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
7/1/2025 6:57:52 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Pentagon.Installer (M)
16.5.29.2

File size:
25.9 MB (27,131,488 bytes)

Product version:
1.0.5251.24719

Copyright:
Copyright (c) ZAYCEV MEDIA GROUP LTD. All rights reserved.

Original file name:
ZaycevNetSetup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\zaycevnetsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/15/2014 1:00:00 AM

Valid to:
4/10/2015 12:59:59 AM

Subject:
CN=LLC Pentagon, O=LLC Pentagon, L=Chelyabinsk, S=Chelyabinsk oblast, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6953C3B39EC862D3EEFA6D7971B66B07

File PE Metadata
Compilation timestamp:
12/24/2012 9:43:11 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
786432:k/CeqqSUsnCX1RQf6ySS0TR559/1eS+6Z5i4m0uCTVHXEG3hV:kbqqSUpAfuBTR5j/1e3c5nm0uCR3EGn

Entry address:
0x25D1C

Entry point:
E8, 1E, 1F, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 80, 00, 00, 00, 72, 0E, 83, 3D, E8, 3E, 45, 00, 00, 74, 05, E9, 7E, 1F, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07, 83, C7, 01, 83, EA...
 
[+]

Code size:
218 KB (223,232 bytes)

The file ZaycevNetSetup.exe has been seen being distributed by the following URL.

http://browserinstall.zaycev.net/zaycevnetsetup.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to front.portal.rambler.ru  (81.19.82.57:443)

TCP (HTTP):
Connects to front.comments.rambler.ru  (81.19.70.23:80)

Remove ZaycevNetSetup.exe - Powered by Reason Core Security