1.exe

Georgi Georgiev

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application 1.exe by Georgi Georgiev has been detected as adware by 23 anti-malware scanners. The file has been seen being downloaded from www.colompia.info and multiple other hosts.
Publisher:
Georgi Georgiev  (signed and verified)

MD5:
5416e3daa1483a827fe1e318a387305e

SHA-1:
18456673f818511adaa6b10708b172088e864c82

SHA-256:
0f7a3a48d5acc700e03a49891850417596f18af19c16eb7c0ba0babb0a09bc0a

Scanner detections:
23 / 68

Status:
Adware

Analysis date:
11/16/2024 1:33:02 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Jaik.4783
758

AhnLab V3 Security
Adware/Win32.MultiPlug
2015.01.08

Avira AntiVirus
Adware/Vonteera.1100880.1
7.11.200.12

avast!
Win32:Adware-gen [Adw]
2014.9-150108

AVG
Win32/DH
2016.0.3236

Bitdefender
Gen:Variant.Jaik.4783
1.0.20.40

Dr.Web
Trojan.DownLoader11.56066
9.0.1.08

Emsisoft Anti-Malware
Gen:Variant.Jaik.4783
8.15.01.08.08

ESET NOD32
Win32/AdWare.Vonteera (variant)
9.10980

Fortinet FortiGate
W32/Farfli.IIP!tr.bdr
1/8/2015

F-Secure
Gen:Variant.Jaik.4783
11.2015-08-01_5

G Data
Gen:Variant.Jaik.4783
15.1.24

IKARUS anti.virus
PUA.Vonteera
t3scan.1.8.6.0

K7 AntiVirus
Adware
13.1814574

Kaspersky
Backdoor.Win32.Farfli
14.0.0.2673

McAfee
Artemis!5416E3DAA148
5600.6892

MicroWorld eScan
Gen:Variant.Jaik.4783
16.0.0.24

Norman
VMProtect.W
11.20150108

Panda Antivirus
Trj/CI.A
15.01.08.08

Qihoo 360 Security
Win32/Trojan.5e3
1.0.0.1015

Reason Heuristics
PUP.GeorgiGeorgiev
15.2.14.11

Sophos
Generic PUA BI
4.98

Trend Micro House Call
TROJ_GEN.R0E9H09A515
7.2.8

File size:
1 MB (1,100,880 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\1.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/6/2014 3:00:00 AM

Valid to:
6/6/2016 2:59:59 AM

Subject:
CN=Georgi Georgiev, O=Georgi Georgiev, STREET="4 Petar Stoinov Str., Chelopechene", L=Sofia, S=Sofia, PostalCode=1617, C=BG

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
50E7161B35AEFC4CA801C951BEF0279A

File PE Metadata
Compilation timestamp:
1/5/2015 9:33:05 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:WHkBH5CeKvyNhXCV4E8BXAfrnkcAqU0AFIJba8Q+nt2SepEz:WHKZCeKv+hyz8grnkQf2IJGdV2

Entry address:
0xE56A

Entry point:
E8, 0A, 6B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, F5, 18, 00, 00, 3B, 0D, A0, 24, 43, 00, 75, 02, F3, C3, E9, 86, 6B, 00, 00, 8B, FF, 51, C7, 01, E4, 84, 42, 00, E8, 7E, 6C, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, BD, FF, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 83, C1, 09, 51, 83, C0, 09, 50, E8, BC, 6C, 00, 00, F7, D8, 59, 1B, C0, 59, 40, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 85, F6...
 
[+]

Entropy:
6.8631

Code size:
155 KB (158,720 bytes)

The file 1.exe has been seen being distributed by the following 6 URLs.

http://www.colompia.info/.../4f70495db.exe

Remove 1.exe - Powered by Reason Core Security