arcadesafarigames.exe

ArcadeSafariInstaller

ArcadeSafari

The application arcadesafarigames.exe by ArcadeSafari has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from s1.arcadesafari.com.
Publisher:
ArcadeSafari  (signed and verified)

Product:
ArcadeSafariInstaller

Version:
3.0.325

MD5:
d1daa9619c0ab68ef956844eabec1178

SHA-1:
b9ddfd0b53b762762621afe733062a49a46fa134

SHA-256:
1c2480f496c88b46f358040879116c8e262a382bdae728b0d3a4353acc7eb738

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 6:04:23 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.EpicPlay (M)
16.7.19.6

File size:
1.3 MB (1,411,248 bytes)

Product version:
3.0.325

Copyright:
Copyright (C) ArcadeSafari

Original file name:
ArcadeSafari

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\arcadesafarigames.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
10/5/2015 9:00:00 PM

Valid to:
11/4/2016 8:59:59 PM

Subject:
CN=ArcadeSafari, O=ArcadeSafari, L=Irvine, S=california, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
69972030BB6696A2D09CFCF4F569F99D

File PE Metadata
Compilation timestamp:
7/29/2015 4:20:13 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:vqOvwRsT+umWWrDK1KGWWrDK1K4sWWrDK1KDQ:xN4W8K1KGW8K1KRW8K1KU

Entry address:
0x1DEC

Entry point:
E8, 6F, 3C, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 38, 50, 51, 00, 89, 0D, 34, 50, 51, 00, 89, 15, 30, 50, 51, 00, 89, 1D, 2C, 50, 51, 00, 89, 35, 28, 50, 51, 00, 89, 3D, 24, 50, 51, 00, 66, 8C, 15, 50, 50, 51, 00, 66, 8C, 0D, 44, 50, 51, 00, 66, 8C, 1D, 20, 50, 51, 00, 66, 8C, 05, 1C, 50, 51, 00, 66, 8C, 25, 18, 50, 51, 00, 66, 8C, 2D, 14, 50, 51, 00, 9C, 8F, 05, 48, 50, 51, 00, 8B, 45, 00, A3, 3C, 50, 51, 00, 8B, 45, 04, A3, 40, 50, 51, 00, 8D, 45, 08, A3, 4C, 50, 51...
 
[+]

Code size:
37.5 KB (38,400 bytes)

The file arcadesafarigames.exe has been seen being distributed by the following URL.

Remove arcadesafarigames.exe - Powered by Reason Core Security