nacl64.exe

Browser

Web Discover

The executable nacl64.exe has been detected as malware by 1 anti-virus scanner.
Publisher:
Web Discover  (signed and verified)

Product:
Browser

Version:
55.0.2859.0

MD5:
1eaa61030c455d31490c246e2d2f938a

SHA-1:
30b9e9b53b5bd2bee53ee9dbc985aea130174789

SHA-256:
7626d44fba9d7ca7de564767b9f31da5a4865da85c8206032062b4746bedd371

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/22/2024 9:12:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.14.8

File size:
5 MB (5,228,256 bytes)

Product version:
55.0.2859.0

Copyright:
Copyright 2016

Original file name:
nacl64.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\webdiscoverbrowser\2.12.2\55.0.2859.0\nacl64.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
2/22/2016 6:00:00 PM

Valid to:
2/22/2017 5:59:59 PM

Subject:
CN=Web Discover, O=Web Discover, L=Wilmington, S=Delaware, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
6A8AE55D88F918454899216E122FA657

File PE Metadata
Compilation timestamp:
11/21/2016 4:48:44 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x2F6394

Entry point:
48, 83, EC, 28, E8, 87, 05, 00, 00, 48, 83, C4, 28, E9, 82, FE, FF, FF, CC, CC, 48, 8B, C4, 48, 89, 58, 08, 48, 89, 68, 10, 48, 89, 70, 18, 48, 89, 78, 20, 41, 56, 48, 83, EC, 20, 4D, 8B, 51, 38, 48, 8B, F2, 4D, 8B, F0, 48, 8B, E9, 49, 8B, D1, 48, 8B, CE, 49, 8B, F9, 41, 8B, 1A, 48, C1, E3, 04, 49, 03, DA, 4C, 8D, 43, 04, E8, AE, F9, FF, FF, 8B, 45, 04, 24, 66, F6, D8, B8, 01, 00, 00, 00, 1B, D2, F7, DA, 03, D0, 85, 53, 04, 74, 11, 4C, 8B, CF, 4D, 8B, C6, 48, 8B, D6, 48, 8B, CD, E8, 4E, 1F, 00, 00, 48, 8B...
 
[+]

Entropy:
6.1054

Code size:
3.1 MB (3,292,160 bytes)

Remove nacl64.exe - Powered by Reason Core Security