TOV Doychkhof – 34% Detection Rate – Amonetize

Hello readers! I was playing around and testing some downloads when I found a file digitally signed by TOV Doychkhof.

TOV Doychkhof uac

It is also possible to check a digital signature by looking at a file’s properties. Here’s a screenshot of the TOV Doychkhof certificate.

TOV Doychkhof certificate

The issue is that FlashPlayer__6741_i1439870194_il674.exe is not an official Adobe Flash Player download. If it was, it should have been digitally signed by Adobe Systems Incorporated. Here’s how the authentic Adobe Flash Player looks like when you double click on it. Notice that the “Verified publisher” says “Adobe Systems Incorporated”.
Adobe Systems Incorporated - Adobe Flashplayer Installer

When I uploaded the TOV Doychkhof file to VirusTotal, it came up with a 34% detection rate. The file is detected as Trojan.Amonetize.341 by DrWeb, Riskware/Amonetize by Fortinet, not-a-virus:AdWare.Win32.Amonetize.sfd by Kaspersky, Artemis by McAfee-GW-Edition and HEUR/QVM10.1.Malware.Gen by Qihoo-360.

TOV Doychkhof virustotal

Did you also find a file digitally signed by TOV Doychkhof? What kind of download was it and where did you find it?

Thanks for reading.