webdev.exe

TODO: <产品名>

KaDefender

The application webdev.exe has been detected as a potentially unwanted program by 7 anti-malware scanners. It runs as a windows Service named “kadefender”. This setup program installs potentially unwanted software on the user's PC at the same time as the expected/marketing software, without adequate consent. The program is typically installed via a form of malvertising While running, it connects to the Internet address li430-19.members.linode.com on port 80 using the HTTP protocol.
Publisher:
KaDefender

Product:
TODO: <产品名>

Description:
KaDefender

Version:
1.0.0.1

MD5:
c9321a3a604b7590b667e0d23a7b3023

SHA-1:
923731222a868376ceadc62bac91e05b50555d5e

SHA-256:
2de4bc3a09a3c1daf5e4e73012c408bf10f48ed0eeca52d18e04bae6a8487224

Scanner detections:
7 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 6:41:43 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Dropper-gen [Drp]
2014.9-140902

Baidu Antivirus
Adware.Win32.SquareNet
4.0.3.1492

IKARUS anti.virus
PUA.SquareNet
t3scan.1.7.5.0

McAfee
Artemis!C9321A3A604B
5600.7019

Microsoft Security Essentials
SoftwareBundler:Win32/SquareNet
1.10904

Panda Antivirus
Trj/Genetic.gen
14.09.02.04

Sophos
Square Network Installer
4.98

File size:
394 KB (403,456 bytes)

Product version:
1.0.0.2

Copyright:
TODO: (C) <公司名>。保留所有权利。

Original file name:
kadefender.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\neworkhost\1409686497\webdev.exe

File PE Metadata
Compilation timestamp:
8/29/2014 12:15:41 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:QWFMapS3ZlPkRDTQjH1uKdgow36HOP3fL6Yu/Q1Oaizefmk:QWFMPsT41uKk36uP3fy/Q1O

Entry address:
0x34213

Entry point:
E8, C5, C0, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 0C, 75, 1D, E8, AC, 2D, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 87, F2, FF, FF, 83, C4, 14, 83, C8, FF, EB, 4D, 8B, 45, 08, 3B, C3, 74, DC, 56, 89, 45, E8, 89, 45, E0, 8D, 45, 10, 50, 53, FF, 75, 0C, 8D, 45, E0, 50, C7, 45, E4, FF, FF, FF, 7F, C7, 45, EC, 42, 00, 00, 00, E8, 49, C1, 00, 00, 83, C4, 10, FF, 4D, E4, 8B, F0, 78, 07, 8B, 45, E0, 88, 18, EB, 0C, 8D, 45, E0, 50, 53, E8, E0, 9C, 00, 00, 59...
 
[+]

Entropy:
6.4690

Code size:
314 KB (321,536 bytes)

Service
Display name:
kadefender

Description:
Kaspself Firewall Defender

Type:
Win32OwnProcess, InteractiveProcess

Depends on:
RPCSS


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to li430-19.members.linode.com  (50.116.4.19:80)

Remove webdev.exe - Powered by Reason Core Security