710e6c9881.exe

Yordan Damyanov

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application 710e6c9881.exe by Yordan Damyanov has been detected as adware by 23 anti-malware scanners. The file has been seen being downloaded from www.colompia.info and multiple other hosts.
Publisher:
Yordan Damyanov  (signed and verified)

MD5:
257398f757c10925a2e29b5528afbf96

SHA-1:
f2741a63d48520cad1548a1377117d894cd57c91

SHA-256:
20ef72057a52d63d0acfe6c0e7e8cfcc65809509df8e882dfef81b41e19b9cc4

Scanner detections:
23 / 68

Status:
Adware

Analysis date:
11/16/2024 1:43:10 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.113234
799

AhnLab V3 Security
Adware/Win32.MultiPlug
2014.11.27

Avira AntiVirus
Adware/ExtCrome.704072
7.11.189.28

avast!
Win32:Adware-CAQ [Adw]
2014.9-141127

Baidu Antivirus
Adware.Win32.Vonteera
4.0.3.141127

Bitdefender
Gen:Variant.Zusy.113234
1.0.20.1655

Comodo Security
ApplicUnwnt
20202

Emsisoft Anti-Malware
Gen:Variant.Zusy.113234
8.14.11.27.05

ESET NOD32
Win32/AdWare.Vonteera (variant)
8.10787

Fortinet FortiGate
Riskware/Vonteera
11/27/2014

F-Secure
Gen:Variant.Zusy.113234
11.2014-27-11_5

G Data
Gen:Variant.Zusy.113234
14.11.24

IKARUS anti.virus
PUA.Vonteera
t3scan.1.8.3.0

K7 AntiVirus
Adware
13.186.14150

Kaspersky
not-a-virus:AdWare.Win32.ExtCrome
14.0.0.2881

McAfee
Artemis!257398F757C1
5600.6933

MicroWorld eScan
Gen:Variant.Zusy.113234
15.0.0.993

Panda Antivirus
Trj/CI.A
14.12.02.07

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.YordanDamyanov.K
14.11.27.17

Sophos
Vonteera
4.98

Trend Micro House Call
Suspicious_GEN.F47V1123
7.2.331

VIPRE Antivirus
Trojan.Win32.Generic
35160

File size:
687.6 KB (704,072 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\jwp36ci8\710e6c9881.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/7/2013 3:00:00 AM

Valid to:
10/8/2015 2:59:59 AM

Subject:
CN=Yordan Damyanov, O=Yordan Damyanov, STREET=19 Dobri Voinikov Str, L=Sofia, S=Sofia, PostalCode=1000, C=BG

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FEEF0D77D0AC7E55D4E7707B384AC901

File PE Metadata
Compilation timestamp:
11/18/2014 10:54:09 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:W7utkQRYqRtsxSFuRdwNj/jdtXPb/Oum2oFwTGJ3T8:W7akQ2US9aNbj/DwFYGJ3T8

Entry address:
0x11EAA

Entry point:
E8, FA, 6D, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, 76, 1A, 00, 00, 3B, 0D, A0, 84, 43, 00, 75, 02, F3, C3, E9, 76, 6E, 00, 00, 8B, FF, 51, C7, 01, DC, C4, 42, 00, E8, 6E, 6F, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, BD, FF, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 83, C1, 09, 51, 83, C0, 09, 50, E8, AC, 6F, 00, 00, F7, D8, 59, 1B, C0, 59, 40, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 85, F6...
 
[+]

Entropy:
7.4373

Code size:
169.5 KB (173,568 bytes)

The file 710e6c9881.exe has been seen being distributed by the following 3 URLs.

Remove 710e6c9881.exe - Powered by Reason Core Security