dailywiki.exe

DailyWiki

The application dailywiki.exe by DailyWiki has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DailyWiki’. This file is typically installed with the program DailyWiki - DailyWiki for Desktop by DailyWiki. While running, it connects to the Internet address 10.im.cz on port 443.
Publisher:
DailyWiki  (signed and verified)

MD5:
341b7490bcc3499ed0c9120d35c22b4c

SHA-1:
8ff41c0ed8fa1c84252f0e3207cd4f1d5240ce8f

SHA-256:
a65430412bbfb1eb63131b6636cf1e1f349aaef0748e223a415c11e02b8ffcc2

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 1:05:56 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DailyWiki (M)
15.10.31.1

File size:
46.4 MB (48,673,472 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\dailywiki\dailywiki.exe

Digital Signature
Signed by:

Authority:
DailyWiki

Valid from:
9/19/2015 3:16:51 AM

Valid to:
9/16/2025 3:16:51 AM

Subject:
CN=DailyWiki, O=DailyWiki, S=Some-State, C=US

Issuer:
CN=DailyWiki, O=DailyWiki, S=Some-State, C=US

Serial number:
00DE81C7E6A224F568

File PE Metadata
Compilation timestamp:
3/4/2015 7:51:42 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
786432:LLJmRGIXff9keaayimwJZHM3SD3K4mNCesWePrumsEUF0pf9UkbuT:LtmRGIXff923imwJZMCDVVesWewFaUkc

Entry address:
0x1C996D1

Entry point:
E8, 9A, 3A, 01, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 8B, 55, 0C, A1, 20, 38, EC, 02, F7, D2, 8B, 4D, 08, 23, D0, 23, 4D, 0C, 0B, D1, 89, 15, 20, 38, EC, 02, 5D, C3, E8, 09, 21, 00, 00, 85, C0, 74, 08, 6A, 16, E8, CC, 21, 00, 00, 59, F6, 05, 20, 38, EC, 02, 02, 74, 21, 6A, 17, E8, A9, 21, 60, 00, 85, C0, 74, 05, 6A, 07, 59, CD, 29, 6A, 01, 68, 15, 00, 00, 40, 6A, 03, E8, A9, F8, FF, FF, 83, C4, 0C, 6A, 03, E8, 16, FC, FF, FF, CC, 55, 8B, EC, 8D, 45, 18, 50, 6A, 00, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75...
 
[+]

Entropy:
6.9074

Code size:
34.9 MB (36,634,112 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DailyWiki

Command:
C:\users\{user}\appdata\roaming\dailywiki\dailywiki.exe su


The file dailywiki.exe has been discovered within the following program.

About 4% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to edge-star-mini-shv-01-frt3.facebook.com  (31.13.92.36:443)

TCP (HTTP SSL):
Connects to rtr3.l7.search.vip.ir2.yahoo.com  (217.12.15.96:443)

TCP (HTTP SSL):
Connects to r1.ycpi.vip.ir2.yahoo.net  (217.12.13.40:443)

TCP (HTTP SSL):
Connects to xx-fbcdn-shv-01-frt3.fbcdn.net  (31.13.92.14:443)

TCP (HTTP SSL):
Connects to xx-fbcdn-shv-01-fra3.fbcdn.net  (31.13.93.7:443)

TCP (HTTP SSL):
Connects to www.novinky.cz  (77.75.76.7:443)

TCP (HTTP):
Connects to server-54-192-44-131.fra6.r.cloudfront.net  (54.192.44.131:80)

TCP (HTTP):
Connects to server-52-85-173-147.fra6.r.cloudfront.net  (52.85.173.147:80)

TCP (HTTP SSL):
Connects to s1-eu.adformnet.akadns.net  (37.157.6.253:443)

TCP (HTTP SSL):
Connects to ls1.host.hit.gemius.pl  (137.74.1.50:443)

TCP (HTTP SSL):
Connects to h.imedia.cz  (77.75.77.9:443)

TCP (HTTP SSL):
Connects to edge-atlas-shv-01-frt3.facebook.com  (31.13.92.2:443)

TCP (HTTP):
Connects to ec2-54-197-238-140.compute-1.amazonaws.com  (54.197.238.140:80)

TCP (HTTP):
Connects to ec2-23-23-100-24.compute-1.amazonaws.com  (23.23.100.24:80)

TCP (HTTP SSL):
Connects to e2.ycpi.vip.lob.yahoo.com  (87.248.114.12:443)

TCP (HTTP SSL):
Connects to e1.ycpi.vip.lob.yahoo.com  (87.248.114.11:443)

TCP (HTTP SSL):
Connects to assigned-81-0-212-199.casablanca.cz  (81.0.212.199:443)

TCP (HTTP SSL):
Connects to ad.seznam.cz  (77.75.76.72:443)

TCP (HTTP SSL):
Connects to a.tribalfusion.com  (204.11.109.65:443)

TCP (HTTP SSL):
Connects to 10.im.cz  (77.75.76.19:443)

Remove dailywiki.exe - Powered by Reason Core Security