awhfb5.tmp

Engaging Apps

This is the installer application for a 50onRed advertising supported software package (displays ads in the browser and may hijack the home and search pages of the web browser). The file awhfb5.tmp by Engaging Apps has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Install System installer. It is also typically executed from the user's temporary directory.
Publisher:
Engaging Apps  (signed and verified)

MD5:
e219611995c2c28c805df88311bafe3c

SHA-1:
57f51557a8ac1f9e5c3b17297fb13c343c2c3d80

SHA-256:
a9cb174c6c7844da4cd92f4048ad65a3aaf453d76d6587d6e1dd6aad566d0b03

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/24/2024 7:34:07 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.50OnRed.EngagingApps.Installer (M)
16.1.30.0

File size:
1.1 MB (1,123,224 bytes)

Installer:
Nullsoft Install System

Common path:
C:\users\{user}\appdata\local\temp\awhfb5.tmp

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/3/2013 7:00:00 PM

Valid to:
6/4/2014 6:59:59 PM

Subject:
CN=Engaging Apps, O=Engaging Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
632EEBD9B987BC680D444D8675A26545

File PE Metadata
Compilation timestamp:
2/19/2012 9:01:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
24576:ptMCWws/oaf5r4AjzuP1dVa8u6RllaJ+XFNwHHStyPSbcvemJB:pGX/rjzuPfVLVMAyPks3

Entry address:
0x4327

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 93, 42, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 94, 42, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 94, 42, 00, 56, A3, 40, 7B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8D, 3B, 00, 00, A3, 9C, 7B, 42, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 01, B3, 40, 00, FF, 15, AC, 94, 42, 00, 83, EC, 14, C7, 44, 24, 04, 02, B3, 40, 00, C7...
 
[+]

Entropy:
7.9533  (probably packed)

Code size:
34.5 KB (35,328 bytes)

Remove awhfb5.tmp - Powered by Reason Core Security