wwe_1.59.101.24.exe

The application wwe_1.59.101.24.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.garniertechnology.com.
MD5:
3dc28eb565bd52c4e0a4633080cb27ca

SHA-1:
eef5ca98af68884e4ed8671c5c834d5c356bf4ab

SHA-256:
8ee0ae7ae9eb849fa03e9e976de8ecfd726004caf714355fbe9f6cf90d2facd3

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 1:41:29 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.5087.0

Reason Heuristics
Adware.Wajam.RE (M)
16.12.10.1

File size:
4.2 MB (4,383,568 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\wwe_1.59.101.24.exe

File PE Metadata
Compilation timestamp:
11/2/2015 1:31:15 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:6TaluzDstX4qtTbRrm4Eb3WPiomeNCnZJWj6jR3tYFWdhv2bObMdHSZMU8fGc:6ekzoh4qldeWPiome+ZJWj49YF62bPSC

Entry address:
0x7B30

Entry point:
74, 07, 05, 29, 0E, 89, A9, 3C, 2D, 68, D0, C5, 5E, 00, 53, F2, F3, 4F, 86, E6, 32, E2, EB, 0E, 8B, C1, 81, D1, BB, A2, A9, D1, 8D, 2D, 67, FB, B8, 4F, 3B, DB, C7, C5, 67, A2, 6B, C1, 11, E9, 80, D7, F6, 84, F5, 76, 0C, 0F, B7, D2, 69, DE, 60, 2E, FB, DC, C6, C2, 33, B5, 2E, B5, 27, 2C, EA, E8, 00, 00, 00, 00, 5F, 2C, 5C, 8B, C3, 0F, AF, F1, 0F, B7, DF, 0F, AF, C1, 80, DB, BE, 2C, 21, 0F, AF, C8, 29, D3, 8D, 2D, 98, F6, 40, 5A, 81, D3, 88, C4, 50, 90, BA, 00, 00, 00, 00, FF, C9, FE, C9, 71, 06, F7, C0, 17...
 
[+]

Entropy:
7.9967  (probably packed)

Code size:
49 KB (50,176 bytes)

The file wwe_1.59.101.24.exe has been seen being distributed by the following URL.

Remove wwe_1.59.101.24.exe - Powered by Reason Core Security