codecmanager.exe

Webteh d.o.o.

The application codecmanager.exe by Webteh d.o.o has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Final Codecs 2008 New Year Edition by Sdxy. While running, it connects to the Internet address chronos.abteam.si on port 80 using the HTTP protocol.
Publisher:
BST  (signed by Webteh d.o.o.)

Description:
BSP Codec DL

Version:
1.0.1.92

MD5:
1a8e331c4cbb0b6f12c776811c94acca

SHA-1:
a8d4faaef560f8439ea9cebe40b2d969161140ea

SHA-256:
f74889f65ec45d9bfc17929d6245bb0c94aeee0462a572706694ac8700f74cd7

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 9:30:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Webtehdoo.M
14.7.27.14

File size:
552.1 KB (565,304 bytes)

Product version:
1.0.1.64

Copyright:
(C) 2008 BST

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\webteh\bsplayer\codecmanager.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/22/2010 2:04:30 PM

Valid to:
2/23/2011 2:04:25 PM

Subject:
E=info@webteh.com, CN=Webteh d.o.o., O=Webteh d.o.o., L=Ljubljana, S=Ljubljana, C=SI

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
01000000000126F57653A8

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:sCE3T/Uv5RlmL4M5nelgR+yBL1pL8EhYM:wT7L4oelgR+ypTQEhYM

Entry address:
0x14C620

Entry point:
60, BE, 00, A0, 4C, 00, 8D, BE, 00, 70, F3, FF, C7, 87, C0, 90, 0F, 00, 40, 52, 5F, 39, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8821

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
524 KB (536,576 bytes)

The file codecmanager.exe has been discovered within the following program.

About 6% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to chronos.abteam.si  (212.18.63.107:80)

TCP (HTTP):
Connects to defiant.abteam.si  (5.9.155.73:80)

TCP (HTTP):
Connects to server6.bsplayer.com  (78.47.3.241:80)

TCP (HTTP):
Connects to bsplayer.com  (212.18.44.40:80)

Remove codecmanager.exe - Powered by Reason Core Security