GeoCube - 66% Detection Rate *

Did you just find a download or a file on your computer that has been digitally signed by GeoCube? Some of the security products refers to the detected files as Trojan.GenericKD.30908742 and Gen:Variant.Graftor.406063. The detection rate for the GeoCube files collected here is 66%. Please read on for more details.

You'll probably notice GeoCube when clicking to run the file. The publisher name is displayed as the "Verified publisher" in the UAC dialog as the screenshot shows:

Screenshot where GeoCube appears as the verified publisher in the UAC dialog

You can view the digital signature details for GeoCube with the following procedure:

  1. Open Windows Explorer and locate the GeoCube file
  2. Right-click on the file and select Properties
  3. Click on the Digital Signatures tab
  4. Click on the View Certificate button

Here is a screenshot of a file that has been digitally signed by GeoCube:

Screenshot of the GeoCube certificate

As you can see in the screenshot above, Windows reports that "This digital signature is OK". This implies that the file has been published by GeoCube and that no one has tampered with the file.

If you click the View Certificate button shown in the screenshot above, you can view all the details of the certificate, such as when it was issued, who issued the certificate, how long it is valid, etc. You can also see the address for GeoCube, such as the street name, city and country.

thawte SHA256 Code Signing CA has issued the GeoCube certificates. You can also see the details of the issuer by clicking the View Certificate button shown in the screenshot above.

GeoCube Files

These are the GeoCube files I have gathered, thanks to the FreeFixer users.

Detection RatioFile Name
47/66sngp.exe
40/66wngplog.exe

Scanner and Detection Names

Here's the detection names for the GeoCube files. I've grouped the detection names by each scanner engine. Thanks to VirusTotal for the scan results.

ScannerDetection Names
AVGWin32:Adware-gen [Adw]
Ad-AwareGen:Variant.Graftor.406063, Trojan.GenericKD.30908742
AhnLab-V3PUP/Win32.Helper.R203797, PUP/Win32.Helper.C2444482
AlibabaAdWare:Win32/Snojan.5f4d9013, AdWare:Win32/Kraddare.f55d5467
Antiy-AVLTrojan/Win32.BTSGeneric, Trojan/Win32.TSGeneric
ArcabitTrojan.Graftor.D6322F, Trojan.Generic.D1D7A146
AvastWin32:Adware-gen [Adw]
AviraADWARE/Adware.Gen7, HEUR/AGEN.1012454
BitDefenderGen:Variant.Graftor.406063, Trojan.GenericKD.30908742
CAT-QuickHealTrojan.Mauvaise.SL1, Trojan.Graftor
ComodoApplicUnwnt@#1uhohauz9cr26, ApplicUnwnt@#19tjuvq3enbfo
CrowdStrikewin/malicious_confidence_80% (D), win/malicious_confidence_60% (D)
Cybereasonmalicious.b14ce0, malicious.41315c
CyrenW32/Application.QTBL-8802, W32/Trojan.KLDE-8385
DrWebTrojan.Adkor.710
ESET-NOD32a variant of Win32/Adware.Kraddare.MS
EmsisoftApplication.Generic (A)
Endgamemalicious (high confidence)
F-SecureAdware.ADWARE/Adware.Gen7, Heuristic.HEUR/AGEN.1012454
FireEyeGeneric.mg.55e2ce2b14ce04ea, Generic.mg.adb9ea941315cca7
FortinetRiskware/Kraddare
GDataGen:Variant.Graftor.406063, Trojan.GenericKD.30908742
IkarusPUA.Kraddare
Invinceaheuristic
JiangminDownloader.Snojan.uy
K7AntiVirusAdware ( 005166b11 )
K7GWAdware ( 005166b11 )
Kasperskynot-a-virus:Downloader.Win32.Snojan.deni
MAXmalware (ai score=100), malware (ai score=99)
McAfeePUP-XEA-NH, PUP-XDY-DH
McAfee-GW-EditionPUP-XEA-NH, PUP-XDY-DH
MicroWorld-eScanGen:Variant.Graftor.406063, Trojan.GenericKD.30908742
MicrosoftAdware:Win32/Kraddare
Paloaltogeneric.ml
PandaTrj/CI.A
Qihoo-360Win32/Virus.Downloader.ff9, Win32/Virus.Adware.dfd
RisingMalware.Heuristic.MLite(93%) (AI-LITE:uUWxkAHW5mEWgXWhsctP8A), Malware.Undefined!8.C (CLOUD)
SUPERAntiSpywareAdware.Kraddare/Variant
SentinelOneDFI - Malicious PE, DFI - Suspicious PE
SophosGeneric PUA IK (PUA), Generic PUA JI (PUA)
SymantecPUA.Gen.2
TencentWin32.Risk.Adware.Sxyg, Win32.Trojan.Graftor.Lqov
TrendMicro-HouseCallTROJ_GEN.R002C0OAF19, TROJ_GEN.R002C0PAF19
VBA32Downloader.Snojan, suspected of Trojan.Downloader.gen.h
ViRobotAdware.Agent.236264.E, Trojan.Win32.Agent.166632
YandexPUA.Downloader!, PUA.Kraddare!
ZillyaAdware.Kraddare.Win32.7255, Adware.Kraddare.Win32.7156
ZoneAlarmnot-a-virus:Downloader.Win32.Snojan.deni

* How the Detection Percentage is Calculated

The detection percentage is based on that I have gathered 132 scan reports for the GeoCube files. 87 of these scan reports came up with some sort of detection. If you like, you can review the full details of the scan results by examining the files listed above.

Analysis Details

The analysis is done on certificates with the following serial numbers:

Comments

No comments posted yet.

Leave a reply