1389167153_the_wedownload_manager1.exe

Entrawb

WeDownload, Ltd

The application 1389167153_the_wedownload_manager1.exe by WeDownload has been detected as adware by 2 anti-malware scanners. The program is a setup application that uses the Midia Downloader installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from bigfiles.hilton.com.
Publisher:
Qyqfivmrovz  (signed by WeDownload, Ltd)

Product:
Entrawb

Description:
Cebxnulaxes

Version:
1.0.0.0

MD5:
3ff92c472c1d11de54ef994e7bc47ba9

SHA-1:
583fd78b80612e92f97623a5a6ae6569938db089

SHA-256:
b24993bbfd32221464c1b367198c93ea290ab4dbc16698acc86b171d76c862b8

Scanner detections:
2 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/26/2024 7:45:21 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Downloader-TOV [PUP]
2014.9-140116

Reason Heuristics
PUP.WeDownload.c
14.8.7.20

File size:
5.3 MB (5,544,256 bytes)

Copyright:
Xvnembheiy

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Midia Downloader

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\1389167153_the_wedownload_manager1.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
2/6/2013 12:00:00 AM

Valid to:
2/11/2016 12:00:00 PM

Subject:
CN="WeDownload, Ltd", O="WeDownload, Ltd", L=Nicosia, C=CY

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0320C5B8F7CE6E92D3665598826A4480

File PE Metadata
Compilation timestamp:
12/4/2012 1:55:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
98304:8UCASO9PPt+s++JoDCHNFGFZjPbTrfBt5z2oaT1S02j496yhDbz:8UCAbH0wFGFZj/Ftsb1Kjyh

Entry address:
0x4323

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, C3, 44, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, C4, 44, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, C4, 44, 00, 56, A3, 40, 3B, 44, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 3B, 44, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, C4, 44, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9969  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file 1389167153_the_wedownload_manager1.exe has been seen being distributed by the following URL.

Remove 1389167153_the_wedownload_manager1.exe - Powered by Reason Core Security