zaxarsetup.4.001.29.exe

ZAXAR LTD

The application zaxarsetup.4.001.29.exe by ZAXAR has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from dl.coin32.com.
Publisher:
ZAXAR LTD  (signed and verified)

MD5:
c8ef4f18bc1a99db5df324124fd7261d

SHA-1:
96330523711abb985e8e363c96cc2bdefd0ba7a6

SHA-256:
bb1c0f22359133e1e981d2e822b9c103ce242003860942956e328699d8dc9470

Scanner detections:
13 / 68

Status:
Adware

Analysis date:
12/25/2024 4:36:07 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.65831
818

Avira AntiVirus
TR/Strictor.177152
7.11.183.194

avast!
Win32:Dropper-gen [Drp]
2014.9-141109

Bitdefender
Gen:Variant.Strictor.65831
1.0.20.1565

Emsisoft Anti-Malware
Gen:Variant.Strictor.65831
8.14.11.09.07

ESET NOD32
Win32/ZaxarGames (variant)
8.10693

Fortinet FortiGate
Riskware/ZaxarGames
11/9/2014

F-Secure
Gen:Variant.Strictor.65831
11.2014-09-11_1

G Data
Gen:Variant.Strictor.65831
14.11.24

McAfee
Artemis!C8EF4F18BC1A
5600.6952

MicroWorld eScan
Gen:Variant.Strictor.65831
15.0.0.939

Reason Heuristics
PUP.Installer.ZAXAR.Q
14.11.9.7

VIPRE Antivirus
Trojan.Win32.Generic
34634

File size:
397.5 KB (406,992 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\zaxarsetup.4.001.29.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/18/2014 4:00:00 AM

Valid to:
11/9/2015 2:59:59 AM

Subject:
CN=ZAXAR LTD, OU=IT, O=ZAXAR LTD, L=Limassol, S=Limassol, C=CY

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
37A90A8AF1DD4C6B68CD54DDB8C6D37D

File PE Metadata
Compilation timestamp:
10/7/2014 8:40:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:WGC7W7BUJle+h+2QoFVntquooWNMR/zMPjHJn+KxkZMMSmB6Q/c/caKErX3WL:ca7keMVnTFmFLSZMVmBXU/7K+c

Entry address:
0x322E

Entry point:
81, EC, D8, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, 34, 81, 40, 00, 55, FF, 15, AC, 82, 40, 00, 6A, 09, A3, 78, 4F, 43, 00, E8, FD, 2E, 00, 00, A3, C4, 4E, 43, 00, 55, 8D, 44, 24, 38, 68, B4, 02, 00, 00, 50, 55, 68, D8, B1, 42, 00, FF, 15, 7C, 81, 40, 00, 68, C0, A2, 40, 00, 68, C0, 3E, 43, 00, E8, 68, 2B, 00, 00, FF, 15, 38, 81, 40, 00, BB, 00, F0, 43, 00, 50, 53, E8, 56, 2B, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file zaxarsetup.4.001.29.exe has been seen being distributed by the following URL.

Remove zaxarsetup.4.001.29.exe - Powered by Reason Core Security