bitlordsetup.exe

BitLord

ClientConnect LTD

The file belongs to the ClientConnect (Conduit/Perion) platform, a utility that bundles and monetizes search toolbars and browser add-ons. The application bitlordsetup.exe, “BitLord Setup ” by ClientConnect has been detected as adware by 7 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from 08291b07dfb043f19794fb8be3a48778.branch-pathdrivek.com. While running, it connects to the Internet address cms.dmccint.com on port 80 using the HTTP protocol.
Publisher:
Perion, Inc.   (signed by ClientConnect LTD)

Product:
BitLord

Description:
BitLord Setup

MD5:
dc9454377b67854937667cfde65cb2f2

SHA-1:
e23bcfff955c21c636430940efeb68d9172597b6

SHA-256:
8db79ca46fa7630230fa3f1e3a9fc98c4177057c2fe6a9b5dd9c44c92403eaed

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Analysis date:
11/5/2024 12:34:08 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.3238

Baidu Antivirus
PUA.Win32.ClientConnect
4.0.3.1515

Dr.Web
Adware.Conduit.179
9.0.1.05

ESET NOD32
Win32/ClientConnect (variant)
9.10965

McAfee
Artemis!DC9454377B67
5600.6894

Reason Heuristics
PUP.Installer.ClientConnect.M
15.1.5.14

VIPRE Antivirus
Conduit
36386

File size:
771.8 KB (790,360 bytes)

Product version:
1.5.0.23

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/3/2014 7:00:00 PM

Valid to:
2/5/2016 6:59:59 PM

Subject:
CN=ClientConnect LTD, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=WL, O=ClientConnect LTD, L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5A60D12BC8FFD4AFAE161FA04715CBC4

File PE Metadata
Compilation timestamp:
7/9/2014 3:58:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:ESxG0S888888888888W88888888888uq8AHNl9boms2lsaJRm71ThpSQo+RdzIeh:LxGsq8Ul9sMljRm7drS5MTQxcGwb72Pq

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.8448

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file bitlordsetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to cms.dmccint.com  (23.67.242.80:80)

 
http://cms.dmccint.com/DynamicOffer/15843518/15864641/?mainofferId=15840084&CurrentStep=2&TotalSteps=4&DownloadBrowser=IE&CType=-1&UserMode=-1&DMVersion=1.3.5.58.15863507.01&Language=US-EN

Remove bitlordsetup.exe - Powered by Reason Core Security