bb8fe61b-f906-4b91-9296-152f96f2f592.exe

WikiBrowser Installer

CLARALABSOFTWARE

The application bb8fe61b-f906-4b91-9296-152f96f2f592.exe by CLARALABSOFTWARE has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from vzbucket.go.im.
Publisher:
The WikiBrowser Authors  (signed by CLARALABSOFTWARE)

Product:
WikiBrowser Installer

Version:
39.0.2132.37

MD5:
fc282c4b4a67f3ade62d8cb3d7551546

SHA-1:
8e2a6282b3dbd7e0711f9c68adc4e341c64c3d05

SHA-256:
09cb9c1b46fd1228d354b6378c50ce1eb81ae2fbb6e717179acd31f74ca04347

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 5:15:18 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.CLARALABSOFTWARE.Installer (M)
15.7.17.7

File size:
38.2 MB (40,022,952 bytes)

Product version:
39.0.2132.37

Copyright:
Copyright 2015 The WikiBrowser Authors. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\bb8fe61b-f906-4b91-9296-152f96f2f592.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/17/2014 3:11:04 PM

Valid to:
12/17/2015 3:11:04 PM

Subject:
CN=CLARALABSOFTWARE, O=CLARALABSOFTWARE, L=Paris, C=FR

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B0709ADBE1F3C

File PE Metadata
Compilation timestamp:
7/16/2015 4:50:41 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
786432:tececiKdwJItJRfvdtgB/lwhz6wnrOg17sfhvWdmXFxE:te/czdwwf/2M2wnrHwhvWdSHE

Entry address:
0x21B1

Entry point:
6A, 00, FF, 15, A4, 40, 40, 00, 50, E8, F2, 08, 00, 00, 59, 50, FF, 15, 90, 40, 40, 00, CC, 55, 8B, EC, 81, EC, 14, 02, 00, 00, 53, 56, 8B, 75, 14, 85, F6, 0F, 84, BE, 00, 00, 00, FF, 75, 08, 8D, 4D, F8, FF, 75, 0C, FF, 75, 10, E8, BF, 0C, 00, 00, 8D, 4D, F8, E8, DC, 0C, 00, 00, 84, C0, 0F, 84, 9D, 00, 00, 00, 8D, 4D, F8, E8, D4, 0C, 00, 00, 83, F8, 01, 0F, 82, 8C, 00, 00, 00, 8D, 4D, F8, E8, C3, 0C, 00, 00, 3B, 05, 98, 15, 40, 00, 77, 7C, FF, 36, 33, C0, BB, 04, 01, 00, 00, 66, 89, 45, F4, 66, 89, 85, EC...
 
[+]

Packer / compiler:
FASM v1.3x

Code size:
8 KB (8,192 bytes)

The file bb8fe61b-f906-4b91-9296-152f96f2f592.exe has been seen being distributed by the following URL.

Remove bb8fe61b-f906-4b91-9296-152f96f2f592.exe - Powered by Reason Core Security