airb4ee.exe

DefaultTab

Search Results, LLC

The application airb4ee.exe, “DefaultTabSetup.exe” by Search Results has been detected as adware by 9 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn.airdlr8.com.
Publisher:
Search Results  (signed by Search Results, LLC)

Product:
DefaultTab

Description:
DefaultTabSetup.exe

Version:
2.2.14.0

MD5:
4ae47178d96d21a2b3c8fb38483dfe04

SHA-1:
4d1f2c4bd3ac3fc1469f2d953f64d68b50d0fd20

SHA-256:
1d059db8b28edc6ccc27501a5e8e3659229ec7041700f23f93a1c5d0be05aacc

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
11/23/2024 4:01:03 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clod091.Trojan
1.3.0.4613

Dr.Web
Adware.Plugin.48
9.0.1.0208

ESET NOD32
Win32/Toolbar.DefaultTab (variant)
8.9857

K7 AntiVirus
Unwanted-Program
13.174.10656

Malwarebytes
PUP.Optional.DefaultTab.A
v2014.07.27.04

McAfee
Artemis!B2D361D6CCFC
5600.6995

NANO AntiVirus
Trojan.Win32.Plugin.crfhgu
0.28.0.57029

Reason Heuristics
PUP.Installer.SearchResults.H
14.8.7.17

Sophos
Generic PUA BM
4.96

File size:
3 MB (3,117,192 bytes)

Product version:
2.2.14.0

Copyright:
Search Results, LLC

Trademarks:
Search Results, LLC

Original file name:
DefaultTabSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\airb4ee.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/24/2012 7:00:00 PM

Valid to:
4/25/2014 6:59:59 PM

Subject:
CN="Search Results, LLC", O="Search Results, LLC", STREET="2751 Hennepin Ave S #252", L=Minneapolis, S=MN, PostalCode=55405, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B6815DF3B6D64839E008D65B53EF0170

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:BFjvnG7/cPQAXryZP549lLTbM1tEr5R209lLiLiqgX7wxaS4MpTyG88GemZ:6WluunAt2r9lLgiqHuMpmD8G

Entry address:
0x63D001

Entry point:
60, E8, 03, 00, 00, 00, E9, EB, 04, 5D, 45, 55, C3, E8, 01, 00, 00, 00, EB, 5D, BB, ED, FF, FF, FF, 03, DD, 81, EB, 00, D0, 63, 00, 83, BD, 88, 04, 00, 00, 00, 89, 9D, 88, 04, 00, 00, 0F, 85, CB, 03, 00, 00, 8D, 85, 94, 04, 00, 00, 50, FF, 95, A9, 0F, 00, 00, 89, 85, 8C, 04, 00, 00, 8B, F0, 8D, 7D, 51, 57, 56, FF, 95, A5, 0F, 00, 00, AB, B0, 00, AE, 75, FD, 38, 07, 75, EE, 8D, 45, 7A, FF, E0, 56, 69, 72, 74, 75, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 56, 69, 72, 74, 75, 61, 6C, 46, 72, 65, 65, 00, 56, 69, 72, 74...
 
[+]

Entropy:
7.9981

Packer / compiler:
ASPack v2.12

Code size:
1.4 MB (1,434,112 bytes)

The file airb4ee.exe has been seen being distributed by the following URL.

Remove airb4ee.exe - Powered by Reason Core Security