air7ea0.exe

betwikx

The application air7ea0.exe by betwikx has been detected as a potentially unwanted program by 20 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn.airdlr6.com.
Publisher:
betwikx  (signed and verified)

MD5:
fec56551f07b84f6d45f9d30cbc6148f

SHA-1:
f6bb33e0607dfbc5881b7ae0fc028cf98d71e934

SHA-256:
e1c51bbe15e7a3145ddd4644b90209710b9ae92ec06a98b8ce2369f94af1ffbe

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
11/26/2024 10:13:37 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.PricePeep.A
1047

Avira AntiVirus
APPL/Betwikx.AP.1
7.11.126.244

AVG
AdInject.Betwikx
2015.0.3525

Bitdefender
Adware.PricePeep.A
1.0.20.420

Bkav FE
W32.Clod858.Trojan
1.3.0.4923

Comodo Security
Application.Win32.AdWare.PricePeep.A
17669

Dr.Web
Adware.Shopper.297
9.0.1.084

Emsisoft Anti-Malware
Adware.PricePeep
8.14.03.25.07

ESET NOD32
Win32/AdWare.PricePeep (variant)
8.9334

Fortinet FortiGate
Adware/JS_PricePeep
3/25/2014

G Data
Adware.PricePeep
14.3.24

IKARUS anti.virus
AdWare.PricePeep
t3scan.2.2.29

Malwarebytes
PUP.Optional.PricePeep.A
v2014.03.25.07

MicroWorld eScan
Adware.PricePeep.A
15.0.0.252

NANO AntiVirus
Trojan.Win32.Shopper.csbcse
0.28.0.57380

nProtect
Adware.PricePeep.A
14.01.24.02

Reason Heuristics
PUP.betwikx.H
14.3.25.7

Trend Micro House Call
TROJ_GEN.F47V0807
7.2.84

Vba32 AntiVirus
AdWare.JS.PricePeep
3.12.24.3

VIPRE Antivirus
Pinball Corporation
25774

File size:
576 KB (589,784 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\air7ea0.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/28/2011 1:00:00 AM

Valid to:
11/27/2013 12:59:59 AM

Subject:
CN=betwikx, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=betwikx, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3A0ED371EEFB729EE95DA7D0B644B32B

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:DxBI0SdCQ05u8JBv1pYXSX6OOY34KKXD2XID+aRCDE:D7I0yCQGD1sJOOJKKT2XI68Cw

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file air7ea0.exe has been seen being distributed by the following URL.

Remove air7ea0.exe - Powered by Reason Core Security