wajam_install.exe

Insta-Download.com

The application wajam_install.exe by Insta-Download.com has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.wajam-download.com.
Publisher:
Insta-Download.com  (signed and verified)

MD5:
2572fdbaa85dc5af3adccb6c0576c1fc

SHA-1:
412a83d0eb77d7e0fd1068ade6ca66e6f315793a

SHA-256:
6ec13c4e4739fde29ce149512bbee807b5ebfbe55218db2c330461f79619a863

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
1/16/2018 8:57:44 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Downloader
2014.07.10

Antiy Labs AVL
Trojan/Win32.TSGeneric
1.0.0.1

Boost by Reason
Optional.InstaDownload.N
188838

Dr.Web
Adware.Searcher.2648
9.0.1.0191

Malwarebytes
PUP.Optional.Wajam.A
v2014.07.10.09

Reason Heuristics
PUP.InstaDownload.N
14.7.17.10

Trend Micro House Call
Suspici.F184F561
7.2.191

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.12.26.3

VIPRE Antivirus
Wajam
31116

Zillya! Antivirus
Trojan.Win32.1DB12147
2.0.0.1851

File size:
2.3 MB (2,382,824 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\1\wajam_install.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/1/2014 2:00:00 AM

Valid to:
5/2/2015 1:59:59 AM

Subject:
CN=Insta-Download.com, O=Insta-Download.com, STREET=4115 Boul Saint-Laurent, L=Montreal, S=Quebec, PostalCode=H2W 1Y7, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
3550B6E62FF3C1E2E800330D7D28C55A

File PE Metadata
Compilation timestamp:
12/5/2009 11:53:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:nCVvhBYeqf5ipnYkSt7CsXltEUyMxwFpS0+3Kjf/EWi:svhWfIYkq7VlzlwF00+3gi

Entry address:
0x36A0

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 88, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, B8, 63, 42, 00, E8, EE, 2E, 00, 00, A3, 04, 63, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, B0, 0C, 42, 00, FF, 15, 58, 81, 40, 00, 68, 10, A8, 40, 00, 68, 00, 5B, 42, 00, E8, F4, 29, 00, 00, FF, 15, B0, 80, 40, 00, BF, 00, C0, 42, 00, 50, 57, E8, E2, 29, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file wajam_install.exe has been seen being distributed by the following URL.

Remove wajam_install.exe - Powered by Reason Core Security