16ab667d-ce22-489f-a890-e2ef6b95528f.exe

York New Labs (Extreme White Limited)

The application 16ab667d-ce22-489f-a890-e2ef6b95528f.exe by York New Labs (Extreme White Limited) has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in.
Publisher:
York New Labs (Extreme White Limited)  (signed and verified)

Version:
106.0.0.0

MD5:
b24079ef0d4a29d5efa9124eb7aee43a

SHA-1:
4fc0ad9f362949dabfd1607feb104a851bd0ea18

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/23/2024 10:22:41 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ExtremeWhite.Bundler.Meta (M)
15.9.24.13

File size:
2.1 MB (2,154,456 bytes)

Product version:
106.0.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Application data\16ab667d-ce22-489f-a890-e2ef6b95528f\16ab667d-ce22-489f-a890-e2ef6b95528f.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/15/2015 1:00:00 AM

Valid to:
4/15/2016 12:59:59 AM

Subject:
CN=York New Labs (Extreme White Limited), O=York New Labs (Extreme White Limited), STREET=Tassou Papadopulu 6 (flat/office 22), L=Nicosia, S=Agios Dometios, PostalCode=2373, C=CY

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00927773AE2A990E6BEB7E5455470BEF66

File PE Metadata
Compilation timestamp:
7/2/2015 10:17:01 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:o6aeb25GucMeB9nVwgmUaq71TspSXrSTOMxS2TiY5lECx8FTJfHTiey:beQLZnVdmVuLfziey

Entry address:
0x1EA000

Entry point:
90, 68, 94, 6B, 7B, 00, 59, 68, 1E, A0, 5E, 00, 5F, BA, 98, 05, 00, 00, 90, 90, 31, 0C, 3A, 83, EA, 02, 83, EA, 02, 90, 90, 75, F3, 90, 7C, 16, 7A, 00, 94, 6B, 7B, 00, 94, 6B, 3B, 00, AA, A1, 69, 00, C4, 43, 65, 00, 4C, 44, 65, 00, 94, DB, 79, 00, 95, 6B, 7B, 00, DC, DB, 2E, 00, 80, CE, 20, 00, B0, CE, 20, 00, F0, FB, 60, 00, 86, CE, 60, 00, B6, CE, 60, 00, DC, CB, 6E, 00, 86, CE, 60, 00, B6, CE, 60, 00, 94, 6B, 7B, 00, 94, 6B, 7B, 00, 94, 6B, 7B, 00, 94, 6B, 7B, 00, 50, DB, 2E, 00, 94, 6B, 7B, 00, 94, 6B...
 
[+]

Code size:
1.4 MB (1,416,192 bytes)

Scheduled Task
Task name:
16AB667D-CE22-489F-A890-E2EF6B95528F

Path:
C:\WINDOWS\Tasks\16AB667D-CE22-489F-A890-E2EF6B95528F.job

Trigger:
Logon (Runs on logon)


Remove 16ab667d-ce22-489f-a890-e2ef6b95528f.exe - Powered by Reason Core Security