binkiland.exe

The application binkiland.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘GoogleChromeAutoLaunch’. This file is typically installed with the program Binkiland by installCore.
Version:
31.0.1650.23

MD5:
5918a40cf0264a20890d988153771f41

SHA-1:
18ff0353cfe9054d3648aa526bcb448ef8749a02

SHA-256:
42984cf297ffb3ac50d861c4c74a1841f8fd304f9fd7d17ada5eab5324beff4b

Scanner detections:
11 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 5:35:19 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Adinstaller.C
726

Baidu Antivirus
Hacktool.Win32.ADInstaller
4.0.3.1529

Bitdefender
Adware.Adinstaller.C
1.0.20.200

Emsisoft Anti-Malware
Adware.Adinstaller
8.15.02.09.01

F-Secure
Adware.Adinstaller.C
11.2015-09-02_2

G Data
Adware.Adinstaller
15.2.25

Kaspersky
not-a-virus:RiskTool.Win32.ADInstaller
14.0.0.2515

MicroWorld eScan
Adware.Adinstaller.C
16.0.0.120

Panda Antivirus
Generic Suspicious
15.02.09.01

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.11.13

File size:
990.5 KB (1,014,272 bytes)

Product version:
31.0.1650.23

Original file name:
binkiland.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\binkiland\application\binkiland.exe

File PE Metadata
Compilation timestamp:
2/4/2015 5:38:00 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:yMCUUl42yySZ9GV9OqhmgaJMI7FOwvmy5tGFZLwkHHYB60Aj+LgYxj1n+Zb:RcI+aPFOwvmyPGbRtRjGPjoZb

Entry address:
0x47242

Entry point:
E8, 58, B2, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, 35, FC, 32, 46, 00, 57, FF, 35, 74, 35, 49, 00, FF, D6, FF, 35, 70, 35, 49, 00, 8B, D8, 89, 5D, FC, FF, D6, 8B, F0, 3B, F3, 0F, 82, 81, 00, 00, 00, 8B, FE, 2B, FB, 8D, 47, 04, 83, F8, 04, 72, 75, 53, E8, AE, B2, 00, 00, 8B, D8, 8D, 47, 04, 59, 3B, D8, 73, 48, B8, 00, 08, 00, 00, 3B, D8, 73, 02, 8B, C3, 03, C3, 3B, C3, 72, 0F, 50, FF, 75, FC, E8, E6, 44, 00, 00, 59, 59, 85, C0, 75, 16, 8D, 43, 10, 3B, C3, 72, 3E, 50, FF, 75, FC, E8...
 
[+]

Entropy:
5.5708

Code size:
392 KB (401,408 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
GoogleChromeAutoLaunch

Command:
"C:\users\{user}\appdata\local\binkil~1\applic~1\binkiland.exe" --no-startup-window


The file binkiland.exe has been discovered within the following program.

Binkiland  by installCore
49% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to rtas-22.btrll.com  (185.62.216.162:80)

TCP (HTTP):

TCP (HTTP SSL):
Connects to a95-101-72-199.deploy.akamaitechnologies.com  (95.101.72.199:443)

TCP (HTTP SSL):
Connects to a92-123-143-233.deploy.akamaitechnologies.com  (92.123.143.233:443)

TCP (HTTP SSL):
Connects to MCEWEB02  (203.116.147.137:443)

TCP (HTTP SSL):
Connects to a118-215.84-135.deploy.akamaitechnologies.com  (118.215.84.135:443)

TCP (HTTP SSL):
Connects to b123cb0f.virtua.com.br  (177.35.203.15:443)

TCP (HTTP):
Connects to ec2-52-208-85-23.eu-west-1.compute.amazonaws.com  (52.208.85.23:80)

TCP (HTTP):
Connects to ec2-23-21-242-90.compute-1.amazonaws.com  (23.21.242.90:80)

TCP (HTTP):
Connects to server-52-84-179-169.gru50.r.cloudfront.net  (52.84.179.169:80)

TCP (HTTP):
Connects to ec2-54-243-155-116.compute-1.amazonaws.com  (54.243.155.116:80)

TCP (HTTP):
Connects to ec2-54-233-142-2.sa-east-1.compute.amazonaws.com  (54.233.142.2:80)

TCP (HTTP):
Connects to ec2-54-225-218-28.compute-1.amazonaws.com  (54.225.218.28:80)

TCP (HTTP):
Connects to ec2-52-2-242-135.compute-1.amazonaws.com  (52.2.242.135:80)

TCP (HTTP):
Connects to ec2-52-206-182-223.compute-1.amazonaws.com  (52.206.182.223:80)

TCP (HTTP):
Connects to ec2-50-19-253-179.compute-1.amazonaws.com  (50.19.253.179:80)

TCP (HTTP SSL):
Connects to ec2-176-34-255-90.eu-west-1.compute.amazonaws.com  (176.34.255.90:443)

TCP (HTTP):
Connects to a201-016-134-056.deploy.akamaitechnologies.com  (201.16.134.56:80)

TCP (HTTP):
Connects to ec2-54-232-204-22.sa-east-1.compute.amazonaws.com  (54.232.204.22:80)

TCP (HTTP):
Connects to bh.namequery.com  (209.53.113.221:80)

Remove binkiland.exe - Powered by Reason Core Security