zaxargamebrowser.exe

ZAXAR LTD

The application zaxargamebrowser.exe by ZAXAR has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
ZAXAR LTD  (signed and verified)

MD5:
7c897ce217b05bb1694a924afa34096c

SHA-1:
fc2705acd846f5eb7b4c3de368a3da3fd0108b0a

SHA-256:
dd03dc7cc1298f884b286a9a44912b58856339271cc9b26480da2f0260f1d78a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 7:43:13 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.10.16.11

File size:
1.2 MB (1,250,720 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\zaxar\zaxargamebrowser.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
3/4/2016 2:00:00 AM

Valid to:
3/5/2018 1:59:59 AM

Subject:
CN=ZAXAR LTD, O=ZAXAR LTD, L=Limassol, S=Limassol, C=CY

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
225B1AB5889506D39643D736D15FE20D

File PE Metadata
Compilation timestamp:
10/16/2016 2:04:29 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:R9XOZNka0Ys5/RqvQxMgPUFYpm+ZUGU+uMhyQEN72SumJUVeGLqkigLLDj:R9X0N/s5Z9PU2pm+qYyFNoukrLT

Entry address:
0x51525

Entry point:
E8, 67, 07, 00, 00, E9, 91, FE, FF, FF, CC, FF, 25, 7C, 11, 46, 00, FF, 25, 78, 11, 46, 00, FF, 25, 74, 11, 46, 00, 83, 3D, AC, 24, 50, 00, 00, 74, 03, 33, C0, C3, 56, 6A, 04, 6A, 20, FF, 15, 88, 11, 46, 00, 59, 59, 8B, F0, 56, FF, 15, 14, 10, 46, 00, A3, AC, 24, 50, 00, A3, A8, 24, 50, 00, 85, F6, 75, 05, 6A, 18, 58, 5E, C3, 83, 26, 00, 33, C0, 5E, C3, 6A, 14, 68, 08, DF, 4E, 00, E8, 26, 08, 00, 00, 83, 65, DC, 00, FF, 35, AC, 24, 50, 00, 8B, 35, 10, 10, 46, 00, FF, D6, 89, 45, E4, 83, F8, FF, 75, 0C, FF...
 
[+]

Code size:
381.5 KB (390,656 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to v-6-07-3-d4260-213.webazilla.com  (206.54.165.213:80)

TCP (HTTP):
Connects to v-5-521-d3806-215.webazilla.com  (206.54.165.215:80)

TCP (HTTP):
Connects to serv7.mediatoday.ru  (195.161.34.116:80)

TCP (HTTP):
Connects to serv1.mediatoday.ru  (195.161.34.114:80)

TCP (HTTP):
Connects to web-eu-ssp-3.facetz.net  (188.42.138.188:80)

TCP (HTTP):
Connects to web-eu-ssp-2.facetz.net  (188.42.131.12:80)

TCP (HTTP):
Connects to c4.3e.559e.ip4.static.sl-reverse.com  (158.85.62.196:80)

TCP (HTTP SSL):
Connects to ec2-52-34-60-95.us-west-2.compute.amazonaws.com  (52.34.60.95:443)

TCP (HTTP SSL):
Connects to ec2-54-236-116-246.compute-1.amazonaws.com  (54.236.116.246:443)

TCP (HTTP SSL):
Connects to ec2-107-21-94-87.compute-1.amazonaws.com  (107.21.94.87:443)

TCP (HTTP SSL):
Connects to a92-123-180-194.deploy.akamaitechnologies.com  (92.123.180.194:443)

Remove zaxargamebrowser.exe - Powered by Reason Core Security