client.exe

The application client.exe has been detected as a potentially unwanted program by 23 anti-malware scanners. This executable runs as a local area network (LAN) Internet proxy server listening on port 49250 and has the ability to intercept and modify all inbound and outbound Internet traffic on the local host. Additionally, the file is typically installed by a number of programs including Rockettab by Rich River Media, LLC and “RocketTab” by Adknowledge, both potentially unwanted software.
MD5:
e38443e1a73099e8ef81b39870d49f49

SHA-1:
7983ea4a4edb395c3651be9b06328fb2d9e6ddc0

SHA-256:
bd65f0c739af7990f903f6ea613b8516d0b3bfc5bdf9cdf61919525f51634a79

Scanner detections:
23 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 9:29:57 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.164387
6087252

avast!
Win32:Adware-CBG [PUP]
141130-1

AVG
Generic
2015.0.3269

Baidu Antivirus
Adware.Win32.RocketTab
4.0.3.14125

Bitdefender
Gen:Variant.Adware.Graftor.164387
1.0.20.1695

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.164387
9.0.0.4668

ESET NOD32
MSIL/Adware.iBryte (variant)
8.10716

Fortinet FortiGate
Adware/RocketTab
12/5/2014

F-Secure
Gen:Variant.Adware.Graftor.164387
11.2014-05-12_6

G Data
Gen:Variant.Adware.Graftor.164387
14.12.24

IKARUS anti.virus
not-a-virus:AdWare.MSIL.RocketTab
t3scan.1.8.5.0

Kaspersky
not-a-virus:AdWare.MSIL.RocketTab
14.0.0.2841

McAfee
Artemis!C3FB53F7D73C
5600.6925

MicroWorld eScan
Gen:Variant.Adware.Graftor.164387
15.0.0.1017

Norman
Gen:Variant.Adware.Graftor.164387
04.12.2014 14:30:06

Panda Antivirus
Trj/Genetic.gen
14.12.05.05

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.5.17

Sophos
Generic PUA MK
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10196

Trend Micro House Call
TROJ_GEN.R047H09KS14
7.2.339

Vba32 AntiVirus
AdWare.MSIL.RocketTab
3.12.26.3

VIPRE Antivirus
AdKnowledge
34748

File size:
5.5 MB (5,812,224 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\search extensions\client.exe

File PE Metadata
Compilation timestamp:
12/5/2014 10:35:26 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:It1d3MupURqzoJLdIPuN7+06Q1mfaRsyhITgB+QrATY:Cd3Mgzo9kuJ+SMTmA

Entry address:
0x1E8F

Entry point:
E8, 3B, 27, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, AC, 87, 98, 00, FF, 15, 3C, 80, 40, 00, 85, C0, 75, 18, 56, E8, ED, 27, 00, 00, 8B, F0, FF, 15, 38, 80, 40, 00, 50, E8, 9D, 27, 00, 00, 59, 89, 06, 5E, 5D, C3, 6A, 0C, 68, B0, A4, 40, 00, E8, 01, 25, 00, 00, 6A, 0E, E8, ED, 2A, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, 00, 7C, 98, 00, BA, FC, 7B, 98, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A...
 
[+]

Entropy:
4.1287

Code size:
25.5 KB (26,112 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:49250/

Local host port:
49250

Default credentials:
No


The file client.exe has been discovered within the following programs.

“RocketTab”  by Adknowledge
RocketTab is a web browser extension that injects display advertising in the user's browser. Ads are displayed in the form of banners and contextual text-links and are both injected in white space areas of the HTML page or over existing ads of the underlying web site.
85% remove it
Rockettab  by Rich River Media, LLC
RocketTab is an adware program that injects advertising in the user's web browser by creating a local proxy server and routing all Internet traffic through that proxy. By re-routing traffic the service will be able to include various ads in the HTML of the displaying web page.
rockettab.com
88% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-208-30-101.compute-1.amazonaws.com  (54.208.30.101:80)

TCP (HTTP):
Connects to xx-fbcdn-shv-01-iad3.fbcdn.net  (31.13.69.203:80)

TCP (HTTP):
Connects to edge-star-mini-shv-01-dft4.facebook.com  (157.240.3.35:80)

TCP (HTTP):
Connects to ec2-52-5-242-226.compute-1.amazonaws.com  (52.5.242.226:80)

TCP (HTTP):
Connects to ec2-52-22-228-216.compute-1.amazonaws.com  (52.22.228.216:80)

TCP (HTTP):
Connects to ec2-52-206-2-43.compute-1.amazonaws.com  (52.206.2.43:80)

TCP (HTTP):
Connects to ec2-50-17-224-168.compute-1.amazonaws.com  (50.17.224.168:80)

TCP (HTTP):
Connects to ec2-50-17-217-59.compute-1.amazonaws.com  (50.17.217.59:80)

TCP (HTTP):
Connects to ec2-50-17-205-172.compute-1.amazonaws.com  (50.17.205.172:80)

TCP (HTTP):
Connects to ec2-34-197-19-240.compute-1.amazonaws.com  (34.197.19.240:80)

TCP (HTTP):
Connects to ec2-23-23-122-81.compute-1.amazonaws.com  (23.23.122.81:80)

TCP (HTTP):
Connects to ec2-184-73-208-133.compute-1.amazonaws.com  (184.73.208.133:80)

TCP (HTTP):
Connects to a96-17-153-8.deploy.akamaitechnologies.com  (96.17.153.8:80)

TCP (HTTP):
Connects to a96-17-153-49.deploy.akamaitechnologies.com  (96.17.153.49:80)

TCP (HTTP):
Connects to a96-16-14-64.deploy.akamaitechnologies.com  (96.16.14.64:80)

TCP (HTTP):

TCP (HTTP):
Connects to 76-110.furanet.com  (91.192.110.76:80)

TCP (HTTP SSL):
Connects to 74.113.237.180.lv.iaccap.com  (74.113.237.180:443)

TCP (HTTP):
Connects to 174-108.furanet.com  (91.192.108.174:80)

TCP (HTTP):
Connects to 161-108.furanet.com  (91.192.108.161:80)

Remove client.exe - Powered by Reason Core Security