88b302c9cc9d7532da1bc1b0df97a6fc.exe

The application 88b302c9cc9d7532da1bc1b0df97a6fc.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address ee-ocsp-origin.ilg.ws.symantec.net on port 80 using the HTTP protocol.
Version:
11.12.1.308

MD5:
150df90099fdf9bae5ff22527ec044b7

SHA-1:
f49bb9c24fd791a8aee9b37354efef5181ccd338

SHA-256:
a9e408800df81a0e2c469e3a77506679743722130473a92dc2ea69d4510a8aad

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 10:55:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
RiskWare.NetFilter
17.2.1.15

File size:
20.4 MB (21,399,040 bytes)

Product version:
11.12.1.308

Copyright:
Copyright (C) 2014

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\1dad916e52f65bc1c2ef14c8147463f7\88b302c9cc9d7532da1bc1b0df97a6fc.exe

File PE Metadata
Compilation timestamp:
1/31/2017 4:48:01 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x147D39C

Entry point:
E9, 54, 00, 00, 00, DA, 17, 04, D0, 81, 6D, 37, F5, 56, 3D, 85, B1, 61, 2C, 99, 95, 97, AB, FB, A6, 44, 78, B1, DD, 1F, 53, 1E, 55, CE, 21, BF, 5B, 43, C3, 22, F7, 32, E9, 8A, A7, 80, A3, 48, 45, 86, 68, A7, 76, DE, 7B, EE, 96, BC, B9, E4, 64, 70, D6, C6, F0, 9E, 8B, B7, A7, 4F, B0, 83, D1, 57, 68, 41, 05, 3A, 2A, AE, D0, 95, E5, 5D, 1A, 34, 9D, 7A, 0D, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90...
 
[+]

Entropy:
1.9928

Packer / compiler:
Xtreme-Protector v1.05

Code size:
19 MB (19,926,528 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):
Connects to a23-15-149-163.deploy.static.akamaitechnologies.com  (23.15.149.163:80)

TCP (HTTP):

TCP (HTTP):
Connects to ocsp.comodoca.com  (178.255.83.1:80)

TCP (HTTP):
Connects to a173-222-148-26.deploy.static.akamaitechnologies.com  (173.222.148.26:80)

TCP (HTTP):
Connects to sg2plpkivs-v01.any.prod.sin2.secureserver.net  (182.50.136.237:80)

TCP (HTTP):
Connects to crl.comodoca.com.cdn.cloudflare.net  (178.255.83.2:80)

TCP (HTTP):

TCP (HTTP):
Connects to a23-59-133-163.deploy.static.akamaitechnologies.com  (23.59.133.163:80)

TCP (HTTP):
Connects to a23-57-213-163.deploy.static.akamaitechnologies.com  (23.57.213.163:80)

TCP (HTTP):
Connects to vip1.g5.cachefly.net  (66.225.197.197:80)

TCP (HTTP):

TCP (HTTP):
Connects to a23-46-101-163.deploy.static.akamaitechnologies.com  (23.46.101.163:80)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

Remove 88b302c9cc9d7532da1bc1b0df97a6fc.exe - Powered by Reason Core Security