69e5ea11620fd5a59091afb6c903a1cc.exe

The application 69e5ea11620fd5a59091afb6c903a1cc.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “3068b3eb943ca28dedc94c99981d0e07”. While running, it connects to the Internet address e3-1230v2.bl-ash0.1.1.2.5.a4.securedservers.com on port 80 using the HTTP protocol.
Description:
EUUQ1HK

Version:
1.68.15.14

MD5:
565146e4feb37fc0d03d7c337ea86a44

SHA-1:
422f24bf9419a2ca5fe366780f6dbd9998120d68

SHA-256:
69d640bda075909350e5558ae65fb8a6596152e153393593768765b7b6c25e20

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 10:53:25 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Wajam
16.10.18.19

File size:
33.9 MB (35,518,464 bytes)

Product version:
1.68.15.14

Copyright:
Copyright (C) 2014

Original file name:
H4N9J3G1BH

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\7bf38b0c0f101ce37245c860d11fb558\69e5ea11620fd5a59091afb6c903a1cc.exe

File PE Metadata
Compilation timestamp:
10/18/2016 4:03:52 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:fNd+Bdo+n5irV9x44pv064i3wKfmlioh/o9PPRMzBa2TKiyKmZ3JHquoT50sK5fQ:fNd+mrJu+7i0rdIiMtonKrT0cZt

Entry address:
0x7CFF36

Entry point:
E8, F2, BC, 01, 00, E9, 7F, FE, FF, FF, E8, 7C, 05, 01, 00, 69, 48, 14, FD, 43, 03, 00, 81, C1, C3, 9E, 26, 00, 89, 48, 14, C1, E9, 10, 81, E1, FF, 7F, 00, 00, 8B, C1, C3, 55, 8B, EC, E8, 58, 05, 01, 00, 8B, 4D, 08, 89, 48, 14, 5D, C3, 55, 8B, EC, 51, 51, 8D, 45, F8, 50, FF, 15, 98, F1, C4, 00, 8B, 4D, F8, 8B, 45, FC, 81, C1, 00, 80, C1, 2A, 6A, 00, 68, 80, 96, 98, 00, 15, 21, 4E, 62, FE, 50, 51, E8, 21, 40, 00, 00, 83, FA, 07, 7C, 0E, 7F, 07, 3D, FF, 6F, 40, 93, 76, 05, 83, C8, FF, 8B, D0, 8B, 4D, 08, 85...
 
[+]

Entropy:
5.2590

Code size:
8.3 MB (8,705,024 bytes)

Service
Display name:
3068b3eb943ca28dedc94c99981d0e07

Type:
Win32OwnProcess


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to e3-1230v2.bl-ash0.1.1.2.5.a4.securedservers.com  (131.153.5.194:80)

Remove 69e5ea11620fd5a59091afb6c903a1cc.exe - Powered by Reason Core Security