vaudix_extension.exe

Kiril Klimko

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application vaudix_extension.exe by Kiril Klimko has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from downloadfriend.net.
Publisher:
Kiril Klimko  (signed and verified)

MD5:
91dd9a6f02fc09dc0d46d119b97d34f5

SHA-1:
373c280df10a940406d4fb7cb4dacbabcabf3ce8

SHA-256:
8a3020aa47cc72bd5cc670457dc2fda4746dc247aa16347eb6ed92c1f575e1ca

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 2:28:52 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick.KirilKlimko (M)
16.2.7.8

File size:
656.4 KB (672,112 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\addons\vaudix_extension.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/3/2013 1:00:00 AM

Valid to:
9/4/2014 12:59:59 AM

Subject:
CN=Kiril Klimko, O=Kiril Klimko, STREET=Perova 21, L=Kiev, S=Kiev, PostalCode=02125, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4F8445DA07CAF9C24D869920925BA182

File PE Metadata
Compilation timestamp:
3/16/2014 12:34:27 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:I/36Cpd8FZT9jfCVgzcMucKBoLbseAk1Zw+xOFq8Vz0yU8IDLZCKQir/ON:I/3ZkZT9jtcMxKBoLbsNFq82yU8PW/2

Entry address:
0x10A4B

Entry point:
E8, 3E, 4A, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, B8, 21, 42, 00, E8, 1F, 21, 00, 00, E8, E0, 07, 00, 00, 0F, B7, F0, 6A, 02, E8, D1, 49, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 90, 37, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.7695  (probably packed)

Code size:
103 KB (105,472 bytes)

The file vaudix_extension.exe has been seen being distributed by the following URL.

Remove vaudix_extension.exe - Powered by Reason Core Security