2b6c94182.exe

Georgi Georgiev

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application 2b6c94182.exe by Georgi Georgiev has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from 91.74.184.36 and multiple other hosts.
Publisher:
Georgi Georgiev  (signed and verified)

MD5:
36295c8ca945d99108fc4ed17a46bde6

SHA-1:
a0e6576e31d2fd189cb6d5a14b4519122aa63914

SHA-256:
56714ee2f6bed65058dc32c27372eb4aaaa81371eb764422dee8a892f29b95a9

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/16/2024 12:00:04 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick.GeorgiGeorgiev (M)
16.3.6.3

File size:
1 MB (1,100,880 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\2b6c94182.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/6/2014 4:00:00 AM

Valid to:
6/6/2016 3:59:59 AM

Subject:
CN=Georgi Georgiev, O=Georgi Georgiev, STREET="4 Petar Stoinov Str., Chelopechene", L=Sofia, S=Sofia, PostalCode=1617, C=BG

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
50E7161B35AEFC4CA801C951BEF0279A

File PE Metadata
Compilation timestamp:
12/19/2014 5:42:33 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:dHkBHTEKvyNhXCV4E8BXAfrnkcAqU0ACBqQn45ntd/k:dHKzEKv+hyz8grnkQf+Tn8

Entry address:
0xE56A

Entry point:
E8, 0A, 6B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, F5, 18, 00, 00, 3B, 0D, A0, 24, 43, 00, 75, 02, F3, C3, E9, 86, 6B, 00, 00, 8B, FF, 51, C7, 01, E4, 84, 42, 00, E8, 7E, 6C, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, BD, FF, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 83, C1, 09, 51, 83, C0, 09, 50, E8, BC, 6C, 00, 00, F7, D8, 59, 1B, C0, 59, 40, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 85, F6...
 
[+]

Entropy:
6.8638

Code size:
155 KB (158,720 bytes)

The file 2b6c94182.exe has been seen being distributed by the following 3 URLs.

http://91.74.184.36/.../6631c7.exe

Remove 2b6c94182.exe - Powered by Reason Core Security