Client.exe

Joltlogic

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application Client.exe by Joltlogic has been detected as adware by 5 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. This executable runs as a local area network (LAN) Internet proxy server listening on port 49171 and has the ability to intercept and modify all inbound and outbound Internet traffic on the local host.
Publisher:
Joltlogic  (signed and verified)

Version:
1.0.5470.15309

MD5:
b13cad672b24f38f47e868b401511bc6

SHA-1:
c7da37291ae2b8215d8fb0d3ba4e1c12a215b883

SHA-256:
e6adaf705d42f1e39e298c891a0e6bd106c8e8665f4dd5d0469e7dc2394061f8

Scanner detections:
5 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/24/2024 4:41:19 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:IBryte-FV [PUP]
2014.9-141224

AVG
Generic
2015.0.3251

ESET NOD32
MSIL/Adware.iBryte (variant)
8.10921

Reason Heuristics
PUP.Joltlogic.G
14.12.24.0

VIPRE Antivirus
AdKnowledge
36024

File size:
852.2 KB (872,672 bytes)

Product version:
1.0.5470.15309

Original file name:
Client.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\geniusbox\client.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/15/2014 5:00:00 PM

Valid to:
7/16/2015 4:59:59 PM

Subject:
CN=Joltlogic, O=Joltlogic, STREET=4600 Madison Ave FL 10, L=Kansas City, S=Missouri, PostalCode=64112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5EE011413A702F6705B25B34B674F3AB

File PE Metadata
Compilation timestamp:
12/23/2014 12:30:36 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:tlSY/pwh5tiSbwx1DRPWgrpgXGMCT7095dT16JSidD0lC6N:t0Y/pwMSbwx1D8/XK49536JS0

Entry address:
0xD5966

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3458

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
846.5 KB (866,816 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:49171/

Local host port:
49171

Default credentials:
No


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to webpooldb41e03.infra.lync.com  (52.112.194.19:443)

TCP (HTTP):
Connects to ec2-54-243-115-164.compute-1.amazonaws.com  (54.243.115.164:80)

TCP (HTTP):
Connects to ec2-50-19-232-40.compute-1.amazonaws.com  (50.19.232.40:80)

TCP (HTTP SSL):
Connects to client.v.dropbox.com  (108.160.172.204:443)

TCP (HTTP):
Connects to server-52-85-142-108.iad12.r.cloudfront.net  (52.85.142.108:80)

TCP (HTTP):
Connects to ec2-54-243-184-36.compute-1.amazonaws.com  (54.243.184.36:80)

TCP (HTTP SSL):
Connects to d.v.dropbox.com  (108.160.172.193:443)

TCP (HTTP):

TCP (HTTP):
Connects to a23-212-41-158.deploy.static.akamaitechnologies.com  (23.212.41.158:80)

TCP (HTTP):
Connects to server-54-192-9-94.lhr3.r.cloudfront.net  (54.192.9.94:80)

TCP (HTTP):
Connects to ec2-23-23-122-81.compute-1.amazonaws.com  (23.23.122.81:80)

TCP (HTTP):
Connects to server-54-192-9-111.lhr3.r.cloudfront.net  (54.192.9.111:80)

TCP (HTTP):
Connects to server-54-192-9-107.lhr3.r.cloudfront.net  (54.192.9.107:80)

TCP (HTTP):
Connects to server-52-85-142-171.iad12.r.cloudfront.net  (52.85.142.171:80)

TCP (HTTP SSL):
Connects to ec2-34-197-126-3.compute-1.amazonaws.com  (34.197.126.3:443)

TCP (HTTP):
Connects to a92-122-148-225.deploy.akamaitechnologies.com  (92.122.148.225:80)

TCP (HTTP):

TCP (HTTP):
Connects to msnbot-207-46-194-14.search.msn.com  (207.46.194.14:80)

TCP (HTTP SSL):
Connects to ec2-52-72-157-241.compute-1.amazonaws.com  (52.72.157.241:443)

TCP (HTTP SSL):
Connects to ec2-52-2-10-61.compute-1.amazonaws.com  (52.2.10.61:443)

Remove Client.exe - Powered by Reason Core Security