setup-d502dd2b71b5.exe

WebCake

Web Cake

This file is part of the Web Cake web browser extension, an adware plugin for various web browsers designed to deliver context based advertising injected directly in the web pages a user is viewing as well opens advertisements that appear independently outside the context of the program, website, or other source the advertisements are promoting. The application setup-d502dd2b71b5.exe by Web Cake has been detected as adware by 23 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. By plugging into the web browser, this extension will inject advertisements both banner and context hyperlinks based on the web sites being visited. It can be installed from the program's website or it may be bundled by third-party software installation programs. It is part of the Yontoo branded browser-extension.
Publisher:
WebCake LLC  (signed by Web Cake)

Product:
WebCake

Description:
Installer

Version:
2013.4.25.2000

MD5:
26be92795a8885ade37cfe7a6d7254b7

SHA-1:
432e39299518354f7c0a462d536da605d64bd80f

SHA-256:
4398bbe5678520a688f47dcc599742cc7262248156adc4e7c2a271a11305086a

Scanner detections:
23 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
12/23/2024 11:19:12 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.WebCake.C
984

Agnitum Outpost
Adware.Generic
7.1.1

Avira AntiVirus
Adware/WebCake.A.188
7.11.127.78

avast!
Win32:Webcake-A [Adw]
2014.9-140526

AVG
AdInject.WebCake
2015.0.3462

Bitdefender
Adware.WebCake.C
1.0.20.730

Comodo Security
ApplicUnwnt
17682

Dr.Web
Adware.Plugin.11
9.0.1.0146

Emsisoft Anti-Malware
Adware.WebCake
8.14.05.26.08

ESET NOD32
Win32/WebCake
8.9341

F-Secure
Adware.WebCake.C
11.2014-26-05_2

G Data
Adware.WebCake
14.5.24

IKARUS anti.virus
AdWare.WebCake
t3scan.2.2.29

K7 AntiVirus
Unwanted-Program
13.175.10963

Malwarebytes
PUP.Optional.WebCake.A
v2014.05.26.08

Microsoft Security Essentials
1.165.247.01

MicroWorld eScan
Adware.WebCake.C
15.0.0.438

nProtect
Adware.WebCake.C
14.01.26.01

Panda Antivirus
Adware/WebCake
14.05.26.08

Quick Heal
Adware.WebCake (Not a Virus)
5.14.12.00

Reason Heuristics
PUP.Installer.WebCake.S
14.8.7.17

Sophos
Generic PUA ED
4.97

VIPRE Antivirus
Yontoo
25852

File size:
283 KB (289,760 bytes)

Product version:
3.00

Copyright:
Copyright (c) 2013 WebCake LLC. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup-d502dd2b71b5.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/8/2013 8:00:00 PM

Valid to:
4/9/2015 7:59:59 PM

Subject:
CN=Web Cake, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Web Cake, L=Carlsbad, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
06B9035EE5A556582D9427CC2C8DD0BC

File PE Metadata
Compilation timestamp:
3/10/2011 9:55:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:D3iwDeAX8wfUAI5bNyAoBoXyJO1h6OwdQ/xaSOvBeyagn7:7/bfULioXP1hqQZVkag7

Entry address:
0x15B4

Entry point:
55, 8B, EC, 81, EC, CC, 05, 00, 00, 53, 56, 33, DB, 57, C6, 85, 34, FA, FF, FF, 00, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 00, 40, 40, 00, FF, 15, 70, 30, 40, 00, 89, 45, F8, 8D, 85, 3C, FE, FF, FF, 50, C7, 85, 3C, FE, FF, FF, 94, 00, 00, 00, FF, 15, 6C, 30, 40, 00, 85, C0, 75, 21, FF, 15, 14, 30, 40, 00, 50, 68, A8, 32, 40, 00, E8, 36, FA, FF, FF, 59, C7, 05, 04, 40, 40, 00, FF, 00, 00, 00, E9, 20, 02, 00, 00, 8B, 35, 68, 30, 40, 00, 68, 94, 32, 40, 00, 68, 84, 32, 40, 00, FF, D6, 50, FF, 15, 64, 30, 40...
 
[+]

Entropy:
7.9639

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file setup-d502dd2b71b5.exe has been seen being distributed by the following URL.

Remove setup-d502dd2b71b5.exe - Powered by Reason Core Security