52e3fb27e66da1715c0113fa.exe

viddyhddownload

Roadstar Media LTD

The application 52e3fb27e66da1715c0113fa.exe by Roadstar Media has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.viddyhddownload.com.
Publisher:
$(^Name)  (signed by Roadstar Media LTD)

Product:
viddyhddownload

Version:
1.0

MD5:
832358e6c7313dc233da4ce85b455994

SHA-1:
934cd3035d2ff61a281afc70716a871301f98c4b

SHA-256:
f0f8d9022a25f2adbcfe2522136e0bc307cbb6cb452e81eb32e151fa506682a3

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
1/11/2025 10:14:41 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
MalSign.Roadstar Media
2015.0.3580

Malwarebytes
PUP.Optional.ViddyHD.A
v2014.01.29.03

McAfee
Artemis!832358E6C731
5600.7236

Reason Heuristics
PUP.RoadstarMedia.Y
14.8.8.0

Rising Antivirus
PE:Trojan.Win32.Generic.137A42C9!326779593
23.00.65.14127

Sophos
Roadstar Media
4.97

Trend Micro House Call
TROJ_GEN.F47V0123
7.2.29

VIPRE Antivirus
Jottix
25850

File size:
192 KB (196,560 bytes)

Product version:
1.0

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\52e3fb27e66da1715c0113fa.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
12/4/2013 7:00:00 PM

Valid to:
12/5/2014 6:59:59 PM

Subject:
CN=Roadstar Media LTD, O=Roadstar Media LTD, L=Tel-Aviv, S=Tel-Aviv, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
093AB5995A92F0A294E993DAA93A2F01

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:pgXdZt9P6D3XJ/ZPL0mjXMU7Q2pzFmaO7yp4tIAwPxnKX5hWHPFiOsixmUpPGbrE:pe34Flgmu2ppmabLP19dhsiNERG

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8392

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file 52e3fb27e66da1715c0113fa.exe has been seen being distributed by the following URL.

Remove 52e3fb27e66da1715c0113fa.exe - Powered by Reason Core Security