ace_stream_media_3.1.12.1.exe

Innovative Digital Technologies

The application ace_stream_media_3.1.12.1.exe by Innovative Digital Technologies has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from laivebi.com and multiple other hosts. While running, it connects to the Internet address static.163.41.251.148.clients.your-server.de on port 80 using the HTTP protocol.
Publisher:
Innovative Digital Technologies  (signed and verified)

MD5:
317b99a43df9ab4d258048191243bc96

SHA-1:
82cee06e757b5c7a71d75aa602cfdc0a7c2f703a

SHA-256:
a81118d5d5918e6c1b105f164e0246af1fedb343c89e8cb286197fb03edf73f6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 12:23:21 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InnovativeDigital (M)
16.12.18.21

File size:
78.5 MB (82,345,072 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ace_stream_media_3.1.12.1.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/14/2016 2:00:00 AM

Valid to:
6/15/2017 1:59:59 AM

Subject:
CN=Innovative Digital Technologies, O=Innovative Digital Technologies, STREET=38/40 A T.Shevchenko Blvd., L=Kyyiv, S=Kyyiv, PostalCode=01032, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7408D72DB44FD7A1F25C606006DCFF6E

File PE Metadata
Compilation timestamp:
7/25/2016 2:55:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x30D9

Entry point:
81, EC, 84, 01, 00, 00, 53, 56, 57, 33, DB, 68, 01, 80, 00, 00, 89, 5C, 24, 18, C7, 44, 24, 10, 98, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, A8, 70, 40, 00, FF, 15, A4, 70, 40, 00, 66, 3D, 06, 00, 74, 11, 53, E8, 7C, 2F, 00, 00, 3B, C3, 74, 07, 68, 00, 0C, 00, 00, FF, D0, BE, 98, 72, 40, 00, 56, E8, F8, 2E, 00, 00, 56, FF, 15, A0, 70, 40, 00, 8D, 74, 06, 01, 38, 1E, 75, EB, 55, 6A, 09, E8, 4F, 2F, 00, 00, 6A, 07, E8, 48, 2F, 00, 00, A3, 04, 37, 42, 00, FF, 15, 44, 70, 40, 00, 53, FF, 15, 88...
 
[+]

Code size:
23.5 KB (24,064 bytes)

The file ace_stream_media_3.1.12.1.exe has been seen being distributed by the following 6 URLs.

http://laivebi.com/Ace_Stream-Laivebi.Com.exe

http://livetv.sx/url.php?i=http://dl.acestream.org/products/acestream-full/.../latest

http://dl.torrentstream.org/products/torrentstream-full/.../latest

http://dl.acestream.org/Ace_Stream_Media_3.1.12.1.exe

http://dl.acestream.org/products/acestream-vlc-1.1.12/.../latest

http://dl.acestream.org/products/acestream-full/.../latest

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to static.163.41.251.148.clients.your-server.de  (148.251.41.163:80)

TCP (HTTP):
Connects to static.164.41.251.148.clients.your-server.de  (148.251.41.164:80)

TCP (HTTP):
Connects to static.165.41.251.148.clients.your-server.de  (148.251.41.165:80)

TCP (HTTP):
Connects to 125.235.4.59.adsl.viettel.vn  (125.235.4.59:80)

Remove ace_stream_media_3.1.12.1.exe - Powered by Reason Core Security