face_istartsurf.exe

4205_face_istartsurf

Taiming Li

The application face_istartsurf.exe by Taiming Li has been detected as adware by 7 anti-malware scanners. The file has been seen being downloaded from d2drfrdurj6mvo.cloudfront.net.
Publisher:
Welnk.com  (signed by Taiming Li)

Product:
4205_face_istartsurf

Description:
Welnk

Version:
6.6.86.1640

MD5:
942cfee99d3466637aa454b5fff45c99

SHA-1:
99d3d2589c6162fe3da0e747a785f493cfbf1049

SHA-256:
717fc7f77a5ff87c82f4a89ace5d6f111a6672516d455be9e8b4bb30654523e4

Scanner detections:
7 / 68

Status:
Adware

Analysis date:
11/1/2024 1:26:12 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.6979

Dr.Web
Adware.Mutabaha.597
9.0.1.0241

herdProtect (fuzzy)
2015.8.29.15

Malwarebytes
PUP.Optional.IStartSurf.ShrtCln
v2015.08.29.03

NANO AntiVirus
Riskware.Win32.Mutabaha.dunath
0.30.24.2668

Quick Heal
PUA.MSJDGBTIR.OD6
8.15.14.00

Reason Heuristics
PUP.Ma Lin.ELEX (M)
15.7.27.9

File size:
276 KB (282,592 bytes)

Product version:
6.6.86.1000

Copyright:
Copyright (C) Welnk 2006

Original file name:
WeLink.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\kam8okwj\face_istartsurf.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
12/8/2014 1:00:00 PM

Valid to:
12/17/2015 1:00:00 AM

Subject:
CN=Taiming Li, O=Taiming Li, L=Shennongjia, S=Hubei, C=CN

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
06C261849DE7A4965D53FC6325143E03

File PE Metadata
Compilation timestamp:
7/23/2015 10:47:48 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:hoxCDGaymlXtzSCelgS/oOvtmOcnxY/HkQhpUQ:hjaNm8ll/oOFmXnenYQ

Entry address:
0x13584

Entry point:
E8, 87, B7, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 18, 95, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 60, 91, 42, 00, C9, C2, 08, 00, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4...
 
[+]

Entropy:
6.2433

Code size:
160 KB (163,840 bytes)

The file face_istartsurf.exe has been seen being distributed by the following URL.

Remove face_istartsurf.exe - Powered by Reason Core Security