ssayfaciconvert_apf_amf_bab.exe

Bitcoktail

The application ssayfaciconvert_apf_amf_bab.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a setup program which is used to install the application. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from d3m37sp3g532jd.cloudfront.net.
Publisher:
Bitcoktail

MD5:
cfba7158a2bf0f7bb79153ead0cdaeab

SHA-1:
409d0764dc10dd493ffb62b305f36d6b1056f159

SHA-256:
450c43cbff23cbbdc5f1ed20d32a2c42ce63342d950555eadba3ee129b6175cf

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 5:32:23 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Toolbar.Babylon
8.6808

Reason Heuristics
PUP.Bitcocktail.Bitcoktail.Meta
15.6.12.12

File size:
1.7 MB (1,785,110 bytes)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ssayfaciconvert_apf_amf_bab.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:7gSyU7etFFMiqoIjh1UZkRXy5SYotBqypyOQbjcOcSwjG7:MSD7evt41UZk12Sg11fX

Entry address:
0xBA20

Entry point:
55, 8B, EC, 83, C4, C0, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, 89, 45, C0, B8, 38, B9, 40, 00, E8, 92, 8E, FF, FF, 33, C0, 55, 68, DB, C0, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 9C, C0, 40, 00, 64, FF, 32, 64, 89, 22, A1, 7C, D3, 40, 00, 8B, 00, E8, 7E, FD, FF, FF, E8, A9, F9, FF, FF, 8D, 55, F0, 33, C0, E8, FF, C9, FF, FF, 8B, 55, F0, B8, 88, EE, 40, 00, E8, F6, 77, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 88, EE, 40, 00, B2, 01, A1, AC, 8B, 40, 00, E8, AE, D2, FF, FF, A3, 8C, EE, 40, 00, 33...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
44.5 KB (45,568 bytes)

The file ssayfaciconvert_apf_amf_bab.exe has been seen being distributed by the following URL.

Remove ssayfaciconvert_apf_amf_bab.exe - Powered by Reason Core Security