9fa922e041eeddf28c50cd01b447b073.exe

3810_air_istartsurf

Taiming Li

The application 9fa922e041eeddf28c50cd01b447b073.exe by Taiming Li has been detected as adware by 21 anti-malware scanners. The file has been seen being downloaded from d2drfrdurj6mvo.cloudfront.net.
Publisher:
WiLink.com  (signed by Taiming Li)

Product:
3810_air_istartsurf

Description:
WiLink

Version:
6.6.86.1620

MD5:
9fa922e041eeddf28c50cd01b447b073

SHA-1:
9233df5154780152169dd5f806450f98dd9bf2c9

SHA-256:
4aa59917e1701a5e0031fa395604ec656460988938a91185288610dd3cbd4c68

Scanner detections:
21 / 68

Status:
Adware

Analysis date:
1/24/2025 4:45:21 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Elex.D
539

Agnitum Outpost
Riskware.Agent
7.1.1

Arcabit
Application.Elex.D
1.0.0.425

Baidu Antivirus
Adware.Win32.ELEX
4.0.3.15814

Bitdefender
Application.Elex.D
1.0.20.1130

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Adware.Mutabaha.412
9.0.1.0226

ESET NOD32
Win32/ELEX.CL potentially unwanted (variant)
9.11717

Fortinet FortiGate
Riskware/Elex
8/14/2015

F-Secure
Application.Elex.D
11.2015-14-08_6

G Data
Application.Elex
15.8.25

herdProtect (fuzzy)
2015.9.27.9

IKARUS anti.virus
PUA.Elex
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.204.16097

Malwarebytes
PUP.Optional.MyStartSearch.A
v2015.08.14.02

MicroWorld eScan
Application.Elex.D
16.0.0.678

Quick Heal
PUA.MSJDGBTIR.OD6
8.15.14.00

Reason Heuristics
PUP.ELEX.TaimingLi (M)
15.8.14.14

Sophos
Generic PUA HM
4.98

Trend Micro House Call
TROJ_GEN.R00GH05EU15
7.2.270

VIPRE Antivirus
Trojan.Win32.Generic
40868

File size:
548 KB (561,120 bytes)

Product version:
6.6.86.1620

Copyright:
Copyright (C) WiLink.com 2008

Original file name:
WiLink.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
12/8/2014 8:00:00 AM

Valid to:
12/16/2015 8:00:00 PM

Subject:
CN=Taiming Li, O=Taiming Li, L=Shennongjia, S=Hubei, C=CN

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0EF3DD8A71CE910929DF8FB28DB3BFD6

File PE Metadata
Compilation timestamp:
5/18/2015 3:25:20 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:USUHCiyLCI6MPm86fRvQI3eanEyt0+TV3i4+TaZnos:nUibLCI6J8GOa9t00SfTaZnp

Entry address:
0x13886

Entry point:
E8, AD, CD, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, A8, F5, 45, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, D0, F1, 45, 00, C9, C2, 08, 00, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00...
 
[+]

Entropy:
6.5083

Code size:
374.5 KB (383,488 bytes)

The file 9fa922e041eeddf28c50cd01b447b073.exe has been seen being distributed by the following URL.

Remove 9fa922e041eeddf28c50cd01b447b073.exe - Powered by Reason Core Security