130214_b4.exe

Woolik technologies ltd

The application 130214_b4.exe by Woolik technologies ltd has been detected as adware by 2 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn.download4desktop.com and multiple other hosts.
Publisher:
Woolik technologies ltd  (signed and verified)

MD5:
d9df24536e21336a9e2171d5f7b646c0

SHA-1:
f2064ee3d49be08f7cdcb764ca6aec381113abf1

SHA-256:
885af0b13774e90c8ff6dee9658da10df7f9c85e29692a71d66c3005530b531d

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
4/24/2024 1:47:39 AM UTC  (today)

Scan engine
Detection
Engine version

Panda Antivirus
Suspicious file
14.03.28.09

Reason Heuristics
PUP.Wooliktechnologiesltd.J
14.8.7.21

File size:
641.5 KB (656,944 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\130214_b4.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/24/2013 9:00:00 PM

Valid to:
7/25/2014 8:59:59 PM

Subject:
CN=Woolik technologies ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Woolik technologies ltd, L=Or Yeuda, S=israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
233D2998915945A85914A5071B609336

File PE Metadata
Compilation timestamp:
7/14/2013 5:09:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:ljG4uMJkrsBg5qd+xvDU7ERXoLmBAC+A8di1V3iwnUPf/aIoRrW5MmCzgSoA:5Gakwg5qMRU7EUqAC+A8UV3iwnU3/4R1

Entry address:
0x310B

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 58, EC, 42, 00, E8, 73, 2D, 00, 00, A3, A4, EB, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, E0, 8F, 42, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, A0, E3, 42, 00, E8, 1D, 2A, 00, 00, FF, 15, 1C, 71, 40, 00, BD, 00, 40, 43, 00, 50, 55, E8, 0B, 2A...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file 130214_b4.exe has been seen being distributed by the following 2 URLs.

Remove 130214_b4.exe - Powered by Reason Core Security