avira internet security 2014 14.0 final full key.exe

Daily apps forfor

The application avira internet security 2014 14.0 final full key.exe by Daily apps forfor has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer.
Publisher:
Daily apps forfor  (signed and verified)

MD5:
f62cb9ac7494413b113679e6bbee40b9

SHA-1:
7651895c10e8bbf17d6b96f4dd168dbb619d599a

SHA-256:
b55fa7dff7d7f585c39b286fd8b844d50532a5071025dd5cb3a20d735df88d8d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 11:30:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.Dailyapp.Installer (M)
16.3.11.23

File size:
584.9 KB (598,984 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\avira internet security 2014 14.0 final full key.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
1/27/2015 7:00:00 AM

Valid to:
1/28/2016 6:59:59 AM

Subject:
CN=Daily apps forfor, O=Daily apps forfor, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6F1E3DDF304CE728A56FBDE7C027105B

File PE Metadata
Compilation timestamp:
12/6/2009 5:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:wNjkrJtbMbbxvtBnVqgvAUoy9yJBoV8DGjtkSoYMHLN8S6tuBtr:wNjyMJtBVqmAtyuxGj+5l8SwuX

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)