deskhomepage_181_1.exe

The application deskhomepage_181_1.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘daydaybuy’. The file has been seen being downloaded from udp.eoo.cm.
MD5:
446bf81f5eb3790d527a6d1b54fc2dd5

SHA-1:
9b1f79b6776a2e7b849b4542f0d5b8339857d091

SHA-256:
84dd28286de6024f4f94c332582bd9857f31c51bc0c3547c6efa28b30ebb4240

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 1:32:00 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Evo-gen [Susp]
160215-2

ESET NOD32
Win32/Adware.Ymeta.A application
8.0.319.0

File size:
1.2 MB (1,289,216 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\deskhomepage_181_1.exe

File PE Metadata
Compilation timestamp:
3/5/2016 8:40:22 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:HtsUkH5cB6RNw3WTEOCBGrT1BGQ+CVr72NsY:HNkHOYs51wrTVTr72V

Entry address:
0x415001

Entry point:
60, E8, 03, 00, 00, 00, E9, EB, 04, 5D, 45, 55, C3, E8, 01, 00, 00, 00, EB, 5D, BB, ED, FF, FF, FF, 03, DD, 81, EB, 00, 50, 41, 00, 83, BD, 22, 04, 00, 00, 00, 89, 9D, 22, 04, 00, 00, 0F, 85, 65, 03, 00, 00, 8D, 85, 2E, 04, 00, 00, 50, FF, 95, 4D, 0F, 00, 00, 89, 85, 26, 04, 00, 00, 8B, F8, 8D, 5D, 5E, 53, 50, FF, 95, 49, 0F, 00, 00, 89, 85, 4D, 05, 00, 00, 8D, 5D, 6B, 53, 57, FF, 95, 49, 0F, 00, 00, 89, 85, 51, 05, 00, 00, 8D, 45, 77, FF, E0, 56, 69, 72, 74, 75, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 56, 69, 72...
 
[+]

Entropy:
7.9502

Packer / compiler:
ASPack v2.12

Code size:
3.1 MB (3,251,712 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
daydaybuy

Command:
C:\users\{user}\appdata\local\temp\bndeskhomepage_181_1.exe r


The file deskhomepage_181_1.exe has been seen being distributed by the following URL.

Remove deskhomepage_181_1.exe - Powered by Reason Core Security