Adware.Variant.FileTour - Certificate “issued” by Comodo and “countersigned” by Symantec & Thawte
Some suspicious/malicious Indicators : File code is packed and obfuscated > Matched Compiler/Packer signature > Packer : UPolyX 0.3 , Compiler : Borland Delphi 2 , File has mutiple PE Anomalies ( Timestamp in PE header is very old ( Jun 1 15:39:05 1988 ) , File sections .rdata & .reloc are shareable , PE file has unusual entropy sections , CRC value set in PE header does not match actual value , Entrypoint in PE header is within an uncommon section , PE file contains zero-size sections , File calls a TLS callback at 0x40A728 [CODE:0x38696] ) , File embeds another file ( type: InnoSetup, location: overlay ) , Reads the active computer name , Reads the registry for installed applications , File get access to Windows built-in privileges ( SetSecurityDescriptorDacl[at]ADVAPI32.DLL ) , File creates guarded memory sections , Looks up many procedures within the same disassembly stream ( Kernel32.dll ) , Drops executable files , File wrotes bytes to the dropped executables , Requested access to a system service ( rasman service ) , Modifies proxy settings , Accesses potentially sensitive information from local browsers , Found more than one unique User-Agent (Inno Downloader) , Contacts 2 domains and 2 hosts , Found malicious artifacts related to “5.254.67.98” and to “35.176.106.236” , File GETs Data from “5.254.67.98:80” (ugastoin.ru) and “35.176.106.236:80” (ec2-35-176-106-236.eu-west-2.compute.amazonaws.com)
Certificate Details :
Algorithm: rsaEncryption
Version: 3
Issuer: /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Code Signing CA
Serial: 199697925695890096781161112996197271758
Serial (Hex): 963c6be6f6a7602b8b24b242951d88ce
Valid from: Aug 17 00:00:00 2017 GMT
Valid until: Jul 9 23:59:59 2018 GMT
C (countryName): RU [5255]
CN (commonName): OOO,PRIVET [4F4F4F2C505249564554]
L (localityName): Ryazan [5279617A616E]
O (organizationName): OOO,PRIVET [4F4F4F2C505249564554]
ST (stateOrProvinceName): RU [5255]
postalCode (postalCode): 390013 [333930303133]
street (streetAddress): ul Vokzalnaya 26 [756C2020566F6B7A616C6E617961203236]