vaudixie_extension.exe

Kiril Klimko

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application vaudixie_extension.exe by Kiril Klimko has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from downloadfriend.net.
Publisher:
Kiril Klimko  (signed and verified)

MD5:
63fbbd779fe690c3b15be185c520cd81

SHA-1:
f347c9eb4f59286d6282ce1897d84912caca1ac5

SHA-256:
427276724a9c8b0ad16783d87d51a9f09dcd7a60e0ab4fdf961e1d349db03dd1

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/20/2024 3:22:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick.KirilKlimko (M)
16.2.7.8

File size:
1.4 MB (1,497,584 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\addons\vaudixie_extension.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/3/2013 1:00:00 AM

Valid to:
9/4/2014 12:59:59 AM

Subject:
CN=Kiril Klimko, O=Kiril Klimko, STREET=Perova 21, L=Kiev, S=Kiev, PostalCode=02125, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4F8445DA07CAF9C24D869920925BA182

File PE Metadata
Compilation timestamp:
3/16/2014 12:34:27 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:r/3ZkZTXdpYXDUMJx01MmoYZAyPjPtMFZIa770cktD:NkZ5N8x01Mzkj1Mge0cG

Entry address:
0x10A4B

Entry point:
E8, 3E, 4A, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, B8, 21, 42, 00, E8, 1F, 21, 00, 00, E8, E0, 07, 00, 00, 0F, B7, F0, 6A, 02, E8, D1, 49, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 90, 37, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.9010  (probably packed)

Code size:
103 KB (105,472 bytes)

The file vaudixie_extension.exe has been seen being distributed by the following URL.

Remove vaudixie_extension.exe - Powered by Reason Core Security