obw_istartsurf.exe

3447_obw_istartsurf

Fuyuan Zhou

The application obw_istartsurf.exe by Fuyuan Zhou has been detected as adware by 9 anti-malware scanners. The file has been seen being downloaded from d2drfrdurj6mvo.cloudfront.net.
Publisher:
HTabp.com  (signed by Fuyuan Zhou)

Product:
3447_obw_istartsurf

Description:
HTabp

Version:
6.6.86.1606

MD5:
76297560417ba7d07624e8cf7dda2029

SHA-1:
cadc146420158b6242d7abe3c244161f5c6dd237

SHA-256:
a0beb8d61059c7d57a759ffcb1dc24c8df9c96d2de5fa45469297c189ad6d7ac

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
11/3/2025 11:39:22 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AVG
Generic
2016.0.3133

Baidu Antivirus
Adware.Win32.ELEX
4.0.3.15420

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Adware.Mutabaha.306
9.0.1.0110

ESET NOD32
Win32/ELEX.CL potentially unwanted (variant)
9.11585

herdProtect (fuzzy)
2015.7.22.7

Malwarebytes
PUP.Optional.IStartSurf.A
v2015.04.20.09

Reason Heuristics
Threat.FuyuanZhou
15.4.20.17

File size:
655.6 KB (671,328 bytes)

Product version:
6.6.86.1606

Copyright:
Copyright (C) HTabp.com 2010

Original file name:
HTabp.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\zziew66c\obw_istartsurf.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
1/15/2015 2:00:00 AM

Valid to:
1/20/2016 2:00:00 PM

Subject:
CN=Fuyuan Zhou, O=Fuyuan Zhou, L=Jilin, S=Jilin, C=CN

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
08CA606335C89594E0B8D9706948A708

File PE Metadata
Compilation timestamp:
3/31/2015 10:45:11 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:i/NAXBvXnouRKH2n+tm1h/a14HpXrr8fywqVXTmf:sNgv4uRJnBO1qpXEfylRTmf

Entry address:
0x29EB7

Entry point:
E8, A8, C9, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, D0, 76, 47, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, A4, 71, 47, 00, C9, C2, 08, 00, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00...
 
[+]

Entropy:
6.4253

Code size:
468.5 KB (479,744 bytes)

The file obw_istartsurf.exe has been seen being distributed by the following URL.

http://d2drfrdurj6mvo.cloudfront.net/.../obw_istartsurf.exe

Remove obw_istartsurf.exe - Powered by Reason Core Security