lly_webssearches.exe

677_tugs

Ma Lin

The application lly_webssearches.exe by Ma Lin has been detected as adware by 12 anti-malware scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.girlzhangtianjiao.com.
Publisher:
Ma Lin  (signed and verified)

Product:
677_tugs

Description:
File Syn

Version:
14.4.4.22

MD5:
7751df62580c28ed00a923bb5b14540f

SHA-1:
6a65ada76cf391f07bdae34a05db79f37eb407f5

SHA-256:
b3f9dbc869d759d329422bdaeb2cbdd092d04b13fdcf780205b69b335a2ca4cd

Scanner detections:
12 / 68

Status:
Adware

Analysis date:
11/27/2024 12:09:22 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Downloader.Generic13
2015.0.3407

Baidu Antivirus
Adware.Win32.ELEX
4.0.3.14721

Dr.Web
Adware.Mutabaha.59
9.0.1.0212

ESET NOD32
Win32/ELEX.AQ potentially unwanted application
8.7.0.302.0

Fortinet FortiGate
Riskware/Elex
7/31/2014

IKARUS anti.virus
PUA.Navegaki
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.SearchHijacker.A
v2014.07.21.08

McAfee
Artemis!E3F23F812A29
5600.7052

Reason Heuristics
PUP.MaLin.Q
14.7.31.23

Rising Antivirus
PE:Worm.Rebhip!1.64F0
23.00.65.14719

Trend Micro House Call
Suspicious_GEN.F47V0716
7.2.212

VIPRE Antivirus
Threat.4150696
31208

File size:
573.1 KB (586,832 bytes)

Product version:
14.4.4.22

Original file name:
FileSyn.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\lly_webssearches.exe

Digital Signature
Signed by:

Authority:
WoSign CA Limited

Valid from:
6/26/2014 5:24:23 AM

Valid to:
6/26/2015 5:24:23 AM

Subject:
CN=Ma Lin, E=chloezhangling@163.com, L=北京市, S=北京市, C=CN

Issuer:
CN=WoSign Class 2 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
0FC83FBFE11653F06215DCA7EACE7E7D

File PE Metadata
Compilation timestamp:
7/14/2014 10:44:54 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:RIjTSPyPg4VkAiNYKbQOTdaicl5xKl0ZjybhBaldr8bq:RIGyFVkAydaiiJyb2Sq

Entry address:
0x22D9F

Entry point:
E8, BE, E8, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, DC, 90, 47, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, BC, 6F, 47, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, DC, 90, 47, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00...
 
[+]

Code size:
383.5 KB (392,704 bytes)

The file lly_webssearches.exe has been seen being distributed by the following URL.

Remove lly_webssearches.exe - Powered by Reason Core Security