nik_color_efex_pro_4_serial_osx_rar_downloader.exe

Safe Decision, Inc

The application nik_color_efex_pro_4_serial_osx_rar_downloader.exe by Safe Decision, Inc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Safe Decision, Inc  (signed and verified)

MD5:
be726d1c969e8574b507d1c85e64296b

SHA-1:
ca5be54d977505f522e131a1ebf64d355aa2d69b

SHA-256:
f62115d9dcfff21268462007f98d978e0ca91258060f6904a9d4da61f9025e56

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 9:09:13 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.EasyDownloads.SafeDecision (M)
16.2.14.10

File size:
4.5 MB (4,718,064 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\nik_color_efex_pro_4_serial_osx_rar_downloader.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
4/19/2010 2:00:00 AM

Valid to:
4/19/2012 1:59:59 AM

Subject:
CN="Safe Decision, Inc", O="Safe Decision, Inc", STREET=16192 Coastal Highway, L=Lewes, S=Delaware, PostalCode=19958, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
6DC4F2ADB6C01EB5AFC087B875031CE2

File PE Metadata
Compilation timestamp:
10/27/2011 5:40:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:GJpyHlRYw6MW5TRxKGUrd6508UBntI3uZ3tremnT+EBNON0CE755xOpdr6mt3U12:GJiz9iT6JrkUBt2uGEBNhl75OOA795

Entry address:
0x6F03BC

Entry point:
68, 23, 7F, A8, 8D, E8, 14, 4D, 1D, 00, 8D, 64, 24, 24, 0F, 82, 46, D5, FF, FF, 66, 3D, 05, 7C, 3B, 04, 24, E9, EB, DF, FF, FF, 29, C9, 68, A1, E6, 08, 84, 8D, 64, 24, 0C, E8, 40, AB, 00, 00, E9, 95, 40, D7, FF, 68, E4, 83, BC, 8D, E8, 64, 45, 1D, 00, 86, 68, 10, 85, BC, 8D, E8, 20, 5B, 1D, 00, E0, 60, 5A, 0B, E9, 5A, F3, FF, FF, AF, 7D, 1F, F2, B8, 62, E6, B3, 79, FA, C0, 6B, 35, F3, B9, 71, 32, D0, 46, 8D, 99, C1, 28, 6B, BF, 1D, 65, 55, D3, 7C, 12, 28, 87, B8, 34, F1, 48, 2B, 68, 1E, 8D, 6E, F7, 98, 63...
 
[+]

Entropy:
7.8014  (probably packed)

Code size:
8.8 MB (9,199,616 bytes)