torrent-play.net_mountand-blade-warband_rus-v.1.127.iso-torrent.exe

Hex Workshop

Falcon Technology

The application torrent-play.net_mountand-blade-warband_rus-v.1.127.iso-torrent.exe by Falcon Technology has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from ec2-52-28-91-210.eu-central-1.compute.amazonaws.com.
Publisher:
BreakPoint Software, Inc.  (signed by Falcon Technology)

Product:
Hex Workshop

Version:
6.8.0.5419

MD5:
4c370bc9ffdf2119645782b107f831bb

SHA-1:
3fdba9bb0b74d3a02396c70f3bef4ea72219831e

SHA-256:
ffef057c9ec2d84087a0c15793847791863a533c04a0264eb42de73893951f2e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/16/2024 7:57:32 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.FileTour (M)
17.2.25.14

File size:
1.2 MB (1,237,736 bytes)

Product version:
6.8.0.5419

Copyright:
Copyright (c) 1995-2014 BreakPoint Software,5419 Inc. All Rights Reserved.

Original file name:
hworks32.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\torrent-play.net_mountand-blade-warband_rus-v.1.127.iso-torrent.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/26/2015 2:00:00 AM

Valid to:
1/27/2016 1:59:59 AM

Subject:
CN=Falcon Technology, O=Falcon Technology, STREET=Dmitrovskoye sh. 39/1, L=Moscow, S=Moscow, PostalCode=127550, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008F8AF4451E61CD493E2A4911EDF99404

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0xCDEF0

Entry point:
55, 8B, EC, 83, C4, F0, B8, C0, D8, 4C, 00, E8, 9C, 8C, F3, FF, A1, 6C, 24, 4D, 00, 8B, 00, E8, 4C, C2, F8, FF, A1, 6C, 24, 4D, 00, 8B, 00, 33, D2, E8, 62, BE, F8, FF, 8B, 0D, 44, 1D, 4D, 00, A1, 6C, 24, 4D, 00, 8B, 00, 8B, 15, 90, 75, 4C, 00, E8, 3E, C2, F8, FF, 8B, 0D, 44, 1F, 4D, 00, A1, 6C, 24, 4D, 00, 8B, 00, 8B, 15, AC, 72, 4C, 00, E8, 26, C2, F8, FF, A1, 6C, 24, 4D, 00, 8B, 00, E8, 9A, C2, F8, FF, E8, 11, 66, F3, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
820 KB (839,680 bytes)

The file torrent-play.net_mountand-blade-warband_rus-v.1.127.iso-torrent.exe has been seen being distributed by the following URL.

http://ec2-52-28-91-210.eu-central-1.compute.amazonaws.com/api/download/iZYvfdx6cVM/lydCquoNukSRRkvU9U8BCQ/lydCquoNukQGhQ7C1NBSvA/.../BrDkFfkKOymdXkZq-xUICbftYza2D-8w8n4PWLgs_TVZDO67bPOSYcz-p5S5nRuaGWxF8iBGgOw