1.exe

Yordan Damyanov

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application 1.exe by Yordan Damyanov has been detected as adware by 21 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.nansq.info and multiple other hosts.
Publisher:
Yordan Damyanov  (signed and verified)

MD5:
f7577a6fc9c05c81dc2576c932453742

SHA-1:
30f1189f61008f6bff2878e23732aeac0151a84e

SHA-256:
633dc1aac7fa6b61805d8cf2092171e0779aa9a47657537570375b70fec92930

Scanner detections:
21 / 68

Status:
Adware

Analysis date:
11/16/2024 1:36:45 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Barys.2925
802

AhnLab V3 Security
Trojan/Win32.Agent
2014.11.25

Avira AntiVirus
TR/Black.Gen2
7.11.188.150

avast!
Win32:Malware-gen
2014.9-141125

AVG
Win32/Blacked
2015.0.3280

Baidu Antivirus
Adware.Win32.Vonteera
4.0.3.141125

Bitdefender
Gen:Variant.Barys.2925
1.0.20.1645

Emsisoft Anti-Malware
Gen:Variant.Barys.2925
8.14.11.25.10

ESET NOD32
Win32/Packed.VMProtect.ABD (variant)
8.10776

Fortinet FortiGate
W32/VMProtBad.A!tr
11/25/2014

F-Secure
Gen:Variant.Barys.2925
11.2014-25-11_3

G Data
Gen:Variant.Barys.2925
14.11.24

IKARUS anti.virus
Trojan.Win32.VMProtect
t3scan.1.8.3.0

K7 AntiVirus
Adware
13.185.14120

McAfee
Artemis!F7577A6FC9C0
5600.6936

MicroWorld eScan
Gen:Variant.Barys.2925
15.0.0.987

Qihoo 360 Security
HEUR/QVM16.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.YordanDamyanov.B
14.11.25.10

Sophos
Mal/VMProtBad-A
4.98

Trend Micro House Call
Suspicious_GEN.F47V1123
7.2.329

VIPRE Antivirus
Trojan.Win32.Generic
35108

File size:
1.4 MB (1,428,552 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\1.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/7/2013 4:00:00 AM

Valid to:
10/8/2015 3:59:59 AM

Subject:
CN=Yordan Damyanov, O=Yordan Damyanov, STREET=19 Dobri Voinikov Str, L=Sofia, S=Sofia, PostalCode=1000, C=BG

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FEEF0D77D0AC7E55D4E7707B384AC901

File PE Metadata
Compilation timestamp:
11/18/2014 11:54:09 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:xIfXENOIcLm+dJ690iSmX0mgV9U6Sq53PHnpb0Es5zUsXkS9S7spu:xIf0NOIcLddZzrmwUK53Pnpb0H5pRAsg

Entry address:
0x11900D0

Entry point:
9C, C7, 04, 24, 5C, A7, FE, D3, E8, 57, 78, FF, FF, 00, 00, 52, 65, 67, 51, 75, 65, 72, 79, 56, 61, 6C, 75, 65, 45, 78, 41, 00, 60, C7, 44, 24, 20, B8, 47, 75, C6, 60, 68, D0, 3A, C0, AB, 9C, C6, 44, 24, 08, 7F, 8D, 64, 24, 48, E9, 06, F5, 12, 00, 26, 18, 19, 86, 02, AC, 53, 4F, DD, 1D, 15, BA, 06, 04, 07, 68, 29, 72, 32, C4, 01, D6, 50, 74, 73, EB, 68, 01, 43, 65, 22, AE, 6F, 34, 74, 43, 44, F9, E5, 11, EE, F2, FB, BC, 8C, ED, DE, CB, C1, 04, 17, F6, B5, 7E, 49, 6D, D0, 71, 8A, CD, 8E, 90, 59, 0A, 55, 8D...
 
[+]

Entropy:
7.8922  (probably packed)

Code size:
169.5 KB (173,568 bytes)

The file 1.exe has been seen being distributed by the following 4 URLs.

http://www.nansq.info/.../dea1cb.exe

http://www.nansq.info/.../16ca50.exe

http://91.74.184.33/.../2fa640ce43.exe

Remove 1.exe - Powered by Reason Core Security