c9fb28dc-ee78-42ad-8d10-4b0f94668d0f.exe

WikiBrowser Installer

CLARALABSOFTWARE

The application c9fb28dc-ee78-42ad-8d10-4b0f94668d0f.exe by CLARALABSOFTWARE has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from vzbucket.go.im.
Publisher:
The WikiBrowser Authors  (signed by CLARALABSOFTWARE)

Product:
WikiBrowser Installer

Version:
39.0.2132.21

MD5:
03c67bf9e4ec52ef7fa9e9e56cbf35ca

SHA-1:
3a6350056de5efed17fefd5398e9a80ed21fabff

SHA-256:
8df3a492e6ccdef4714b2892ccf82cd7d9bf2b2cf1fd2a243bb39fcadb14321b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/1/2024 5:23:08 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.CLARALABSOFTWARE
15.5.18.15

File size:
37.3 MB (39,075,752 bytes)

Product version:
39.0.2132.21

Copyright:
Copyright 2015 The WikiBrowser Authors. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\c9fb28dc-ee78-42ad-8d10-4b0f94668d0f.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/17/2014 9:11:04 AM

Valid to:
12/17/2015 9:11:04 AM

Subject:
CN=CLARALABSOFTWARE, O=CLARALABSOFTWARE, L=Paris, C=FR

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B0709ADBE1F3C

File PE Metadata
Compilation timestamp:
5/15/2015 7:03:14 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
786432:HR6ZqmH26MNrbadZdhxDxfB2x0sdwvEykFEAjEnuE8eqebClfSA:I1260rbaPT7oJGvEfFEAjEHry5

Entry address:
0x21B1

Entry point:
6A, 00, FF, 15, A4, 40, 40, 00, 50, E8, F2, 08, 00, 00, 59, 50, FF, 15, 90, 40, 40, 00, CC, 55, 8B, EC, 81, EC, 14, 02, 00, 00, 53, 56, 8B, 75, 14, 85, F6, 0F, 84, BE, 00, 00, 00, FF, 75, 08, 8D, 4D, F8, FF, 75, 0C, FF, 75, 10, E8, BF, 0C, 00, 00, 8D, 4D, F8, E8, DC, 0C, 00, 00, 84, C0, 0F, 84, 9D, 00, 00, 00, 8D, 4D, F8, E8, D4, 0C, 00, 00, 83, F8, 01, 0F, 82, 8C, 00, 00, 00, 8D, 4D, F8, E8, C3, 0C, 00, 00, 3B, 05, 98, 15, 40, 00, 77, 7C, FF, 36, 33, C0, BB, 04, 01, 00, 00, 66, 89, 45, F4, 66, 89, 85, EC...
 
[+]

Entropy:
8.0000

Packer / compiler:
FASM v1.3x

Code size:
8 KB (8,192 bytes)

The file c9fb28dc-ee78-42ad-8d10-4b0f94668d0f.exe has been seen being distributed by the following URL.

Remove c9fb28dc-ee78-42ad-8d10-4b0f94668d0f.exe - Powered by Reason Core Security