kiyacdkvzx.exe

Weather Alert

Fast Lane Development

The application kiyacdkvzx.exe by Fast Lane Development has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Fast Lane Development  (signed and verified)

Product:
Weather Alert

Description:
WeatherAlert

Version:
1.0.0.0

MD5:
8d6df3ac92c09f9a42e7f2f3686e9313

SHA-1:
c6009bbb43285888ef313e457bdf11ede6720f63

SHA-256:
a966c02bb9f6cf4afdf36884546970f7606e047c79f19fbe59fd37048205ec1d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/29/2024 12:33:34 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt.FastLane (M)
16.3.8.23

File size:
46.7 KB (47,808 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Fast Lane Development 2016

Original file name:
WeatherAlert.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\jmxrnooe\dat\kiyacdkvzx.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/3/2015 1:36:21 PM

Valid to:
11/3/2016 1:36:21 PM

Subject:
CN=Fast Lane Development, O=Fast Lane Development, L=Warrens, S=Saint Michael, C=BB

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11211B8F1051797C18F993CD4F0D6C793447

File PE Metadata
Compilation timestamp:
3/8/2016 1:42:03 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:l84ALcq9G4pAyUw2QevAKIBomeaDgunVcM6B0Ai7V4UqwCwe4p3PEwV:llALJ5ayoQGTIBomeaDDWM6Cb7eaN

Entry address:
0xB83E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
38.5 KB (39,424 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to a23-200-86-143.deploy.static.akamaitechnologies.com  (23.200.86.143:80)

Remove kiyacdkvzx.exe - Powered by Reason Core Security