webcam-v69b-1-3-mega-driver-windows-drv.exe

oTweak Software LLC

The application webcam-v69b-1-3-mega-driver-windows-drv.exe by oTweak Software has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.driverstt.com.
Publisher:
oTweak Software LLC  (signed and verified)

MD5:
b31b6968d0d5e93599695800fffe9627

SHA-1:
34b3fb0927ac52cbe577f3b791da1ff84d42cae4

SHA-256:
f38b04a18235d28338fb010562935a51331d6d80d56dadf892d3cf329d49706f

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 9:52:38 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Siggen6.33552
9.0.1.0120

herdProtect (fuzzy)
2015.7.30.19

NANO AntiVirus
Riskware.Nsis.Unwanted.dpybkw
0.30.24.1636

Reason Heuristics
PUP.oTweak.Optional.Installer.Meta (L)
15.12.1.12

Trend Micro House Call
Suspicious_GEN.F47V0429
7.2.120

File size:
3.6 MB (3,729,704 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\webcam-v69b-1-3-mega-driver-windows-drv.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
3/5/2015 1:00:00 AM

Valid to:
3/5/2017 12:59:59 AM

Subject:
CN=oTweak Software LLC, O=oTweak Software LLC, L=Rostov-Na-Donu, S=Rostovskaya obl., C=RU

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1BA315B89D1AF7C2CB153F29392B2B78

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:zWMAvdm8vYOmxLg4tiR2nUL2MFrC8bGDSd+UnVJ/6e86XDpRpcIrpdF+eHxSzk1R:2vdL+xLHqL2MTVJiLYptHii+lNAdVLN

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file webcam-v69b-1-3-mega-driver-windows-drv.exe has been seen being distributed by the following URL.

Remove webcam-v69b-1-3-mega-driver-windows-drv.exe - Powered by Reason Core Security