obw_webssearches1210.exe

1671_obw_webssearches

One Syn

The application obw_webssearches1210.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. The file has been seen being downloaded from dl1.downserver3.com.
Publisher:
One Syn

Product:
1671_obw_webssearches

Description:
Syn worker

Version:
6.2.7601.1028

MD5:
c9aba985227312f8e25236a58e6a7c62

SHA-1:
5c110b33c49e5d40eb12da02c48677390c89a967

SHA-256:
927d1abe227ca1fe86694d80f081843eb367d5a0984e974ca5737a0f87a2d78f

Scanner detections:
10 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 2:49:32 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160310-2

Dr.Web
Adware.Mutabaha.80, Win32.Sector.12
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality.OG
11.5.0.6191

ESET NOD32
Win32/Sality.NAU virus
7.0.302.0

F-Prot
W32/Sality.AK
4.6.5.141

F-Secure
Win32.Sality.OG
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Program.Artemis!9E0B42128315
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.215.1919.0

Norman
Win32.Sality.OG
29.02.2016 03:11:57

File size:
391.9 KB (401,272 bytes)

Product version:
6.2.7601.1028

Copyright:
One Syn

Original file name:
Worker.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\obw_webssearches1210.exe

File PE Metadata
Compilation timestamp:
10/9/2014 1:02:16 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:tfIjbIM+9RosYWUOfXgVavL4ZXnIjN3TYRdjllLEO/Ih:tfKr+925OvlvMZXnIp32tE4+

Entry address:
0x17BA6

Entry point:
60, E8, 28, 00, 00, 00, BA, 4B, 9E, DF, 98, 02, 65, 6B, 32, 55, B1, E6, 87, 06, B8, 86, 87, E2, AA, 12, 84, 6C, AB, 72, 50, DA, 97, 18, EA, 01, 1D, 87, D0, 33, 02, 0C, DA, EC, 3D, 7E, 5B, 3B, CB, 8A, C6, 0F, A3, D8, 78, 06, 8B, CD, 48, 38, F0, F3, 81, C3, 6C, AE, 3C, 00, 0F, C9, 47, 89, E9, 0F, C1, C8, 0F, A5, F7, 81, EB, 18, FA, 38, 00, 8D, 3D, 3C, 0F, 96, 01, 8B, D3, 0F, BD, EF, F6, DC, 0F, A3, FD, 52, 03, E9, FF, C1, 70, 05, 8B, EE, 41, 8B, CD, 81, C3, 59, 07, 00, 00, 0F, A5, F7, 0F, CF, 0F, A4, F7, 94...
 
[+]

Entropy:
6.3516

Packer / compiler:
ASPack v1.08.04

Code size:
191.5 KB (196,096 bytes)

The file obw_webssearches1210.exe has been seen being distributed by the following URL.

Remove obw_webssearches1210.exe - Powered by Reason Core Security