566d738dafe.exe

Kaydar LLC

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application 566d738dafe.exe by Kaydar has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Kaydar LLC  (signed and verified)

MD5:
a241a99970a2d53a83a052402f5f07ca

SHA-1:
1dbdd2b9dbde1daeaaaeba6d04be27b26d0ec715

SHA-256:
41dedaf570ce17ed85cd8d10fde2e916e10f6449cb58d5b20cfc50898f8965c3

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/24/2024 3:36:31 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick (M)
16.9.10.19

File size:
1.1 MB (1,134,560 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\566d738dafe.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/12/2015 7:14:19 AM

Valid to:
9/24/2015 10:07:10 AM

Subject:
E=kaydarmail@gmail.com, CN=Kaydar LLC, O=Kaydar LLC, L=Dnipropetrovsk, C=UA

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11217A57B813A060AF912C2EFE9F51A75C3B

File PE Metadata
Compilation timestamp:
3/8/2013 8:26:59 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:CEKQ9gPgYMGNaO9Jme5iXj+XV1/y+Zbb7e29l:CJk+MCaaJme59ryYHe6l

Entry address:
0xB8C09

Entry point:
E8, FE, 13, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 60, F1, 4F, 00, E8, 11, 19, 00, 00, E8, CB, 15, 00, 00, 0F, B7, F0, 6A, 02, E8, 91, 13, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 40, 03, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.3921

Code size:
759.5 KB (777,728 bytes)

Remove 566d738dafe.exe - Powered by Reason Core Security