wajam_install.exe

Wajam

Wajam Internet Technologies Inc

The file is part of Wajam, a web browser extension that injects social search integration into various search portals such as Google. The application wajam_install.exe by Wajam Internet Technologies Inc has been detected as adware by 2 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.wajam.com.
Publisher:
Wajam Internet Technologies Inc  (signed and verified)

Product:
Wajam

Version:
2.03

MD5:
d47dfe5e5d3883f16823a495cff6d392

SHA-1:
a7474a5abcbf088d4717d190deac5db8044bc8ab

SHA-256:
7bed3c50b5a5b7bab1bba3205e24188477ab6afa63b15bd7f24846eb71560156

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
5/10/2024 4:48:01 PM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.WajamInternetTechnologies
188838

Reason Heuristics
PUP.Wajam.WajamInternetTechnologies.Installer (M)
16.1.24.2

File size:
461.8 KB (472,864 bytes)

Copyright:
© Wajam. All right reserved.

Trademarks:
Wajam – Great minds search alike.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\wajam_install.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/9/2013 2:00:00 AM

Valid to:
7/10/2018 1:59:59 AM

Subject:
CN=Wajam Internet Technologies Inc, O=Wajam Internet Technologies Inc, STREET=4115 Saint-Laurent Blvd, L=Montreal, S=Quebec, PostalCode=H2W 1Y7, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008DAB5910F20F42BD7B16C6EBC90BB13C

File PE Metadata
Compilation timestamp:
12/5/2009 11:53:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:uyiAm3jIe77IZD+I97f0N5BTInFx5cJ7ZMg5ZozV2E:uyiAmTx7cZSI9Lo/6FcL5ZqV1

Entry address:
0x36A0

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 88, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, B8, 63, 42, 00, E8, EE, 2E, 00, 00, A3, 04, 63, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, B0, 0C, 42, 00, FF, 15, 58, 81, 40, 00, 68, 10, A8, 40, 00, 68, 00, 5B, 42, 00, E8, F4, 29, 00, 00, FF, 15, B0, 80, 40, 00, BF, 00, C0, 42, 00, 50, 57, E8, E2, 29, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file wajam_install.exe has been seen being distributed by the following URL.

Remove wajam_install.exe - Powered by Reason Core Security