nacl64.exe

Browser

Web Discover

The executable nacl64.exe has been detected as malware by 1 anti-virus scanner.
Publisher:
Web Discover  (signed and verified)

Product:
Browser

Version:
55.0.2859.0

MD5:
6212210d79fb68dbed776fc2276c8216

SHA-1:
749169855a4dde71d1c2cab8afeb1958c3045ada

SHA-256:
b3fcaf016fcfb6eb2f0b85e170e8341841e11864db644bd900d02f9a65075761

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/3/2021 10:02:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.4.9

File size:
5 MB (5,228,256 bytes)

Product version:
55.0.2859.0

Copyright:
Copyright 2016

Original file name:
nacl64.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\webdiscoverbrowser\2.28.2\55.0.2859.0\nacl64.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
1/9/2017 6:00:00 PM

Valid to:
2/23/2018 5:59:59 PM

Subject:
CN=Web Discover, O=Web Discover, L=Wilmington, S=Delaware, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
409E4C9DD669272BE87359D12792FEE8

File PE Metadata
Compilation timestamp:
3/2/2017 6:36:15 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x2F6394

Entry point:
48, 83, EC, 28, E8, 87, 05, 00, 00, 48, 83, C4, 28, E9, 82, FE, FF, FF, CC, CC, 48, 8B, C4, 48, 89, 58, 08, 48, 89, 68, 10, 48, 89, 70, 18, 48, 89, 78, 20, 41, 56, 48, 83, EC, 20, 4D, 8B, 51, 38, 48, 8B, F2, 4D, 8B, F0, 48, 8B, E9, 49, 8B, D1, 48, 8B, CE, 49, 8B, F9, 41, 8B, 1A, 48, C1, E3, 04, 49, 03, DA, 4C, 8D, 43, 04, E8, AE, F9, FF, FF, 8B, 45, 04, 24, 66, F6, D8, B8, 01, 00, 00, 00, 1B, D2, F7, DA, 03, D0, 85, 53, 04, 74, 11, 4C, 8B, CF, 4D, 8B, C6, 48, 8B, D6, 48, 8B, CD, E8, 4E, 1F, 00, 00, 48, 8B...
 
[+]

Entropy:
6.1054

Code size:
3.1 MB (3,292,160 bytes)

Remove nacl64.exe - Powered by Reason Core Security