{blocked}.exe

Alexey Kurilenko

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application {blocked}.exe by Alexey Kurilenko has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from skipperham.info.
Publisher:
Alexey Kurilenko  (signed and verified)

MD5:
61c5270fe3d7f5cbe27ae5d3c5594f50

SHA-1:
1c43de90e76d0e6e69df124cad1087bce91b92fb

SHA-256:
f7e1a07413178e69869866b7830acaff17dc20ee5a5db4cb6a36ee4c1fca5938

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
8/15/2025 10:43:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick (M)
16.8.1.7

File size:
1.3 MB (1,348,472 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\pass a soccer ball .mp4.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
6/17/2014 4:20:17 PM

Valid to:
6/17/2015 4:20:17 PM

Subject:
E=Alexey.kurilenko@hotmail.com, CN=Alexey Kurilenko, O=Alexey Kurilenko, C=RU

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
15D51642691B3EE20985639A8FE865DD

File PE Metadata
Compilation timestamp:
5/10/2013 7:56:34 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:JzK+8+yAWu4t3jcy2FQL8VgUVnMaHbiwryfrNrODYjv:JzK+8ftdYNQLO5MbGyfrNrhb

Entry address:
0x17C6A

Entry point:
E8, 1D, 39, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 60, 94, 45, 00, E8, 50, 11, 00, 00, E8, EA, 3A, 00, 00, 0F, B7, F0, 6A, 02, E8, B0, 38, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, C2, 09, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.7888

Code size:
336 KB (344,064 bytes)

The file {blocked}.exe has been seen being distributed by the following URL.

Remove {blocked}.exe - Powered by Reason Core Security