corrales.exe

Corrales

The application corrales.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named 48574358 triggered to execute each time a user logs in. While running, it connects to the Internet address server-52-85-94-212.jfk5.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
Corrales

Product:
Corrales

Version:
7.6.4.21

MD5:
7eb0bf5b04c003cfb706496cf2d9228d

SHA-1:
2ca56d7784632dd0ac56f1405c5b27f704bb63b3

SHA-256:
085544ebd7cee1be1667001bd064ca9ed89180fc331f6734472a2a1606dbfd92

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 8:42:40 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/Adware.Dotdo.AP application
6.3.12010.0

Reason Heuristics
Adware.Dotdo.ET (M)
17.2.7.18

File size:
9 KB (9,216 bytes)

Product version:
7.6.4.21

Copyright:
Copyright © Corrales 2017

Trademarks:
© 2017 Corrales

Original file name:
corrales.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\witz\corrales.exe

File PE Metadata
Compilation timestamp:
1/31/2017 12:23:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x362E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.1298

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
6 KB (6,144 bytes)

Scheduled Task
Task name:
48574358

Trigger:
Logon (Runs on logon)

Description:
4857435848574358


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to pr-bh.pbp.vip.bf1.yahoo.com  (72.30.2.182:80)

TCP (HTTP):
Connects to ec2-52-206-114-171.compute-1.amazonaws.com  (52.206.114.171:80)

TCP (HTTP):
Connects to cdce.nym011.internap.com  (63.251.19.10:80)

TCP (HTTP):
Connects to ec2-54-236-87-23.compute-1.amazonaws.com  (54.236.87.23:80)

TCP (HTTP):
Connects to ec2-52-205-51-172.compute-1.amazonaws.com  (52.205.51.172:80)

TCP (HTTP):
Connects to server-52-85-94-212.jfk5.r.cloudfront.net  (52.85.94.212:80)

TCP (HTTP):
Connects to static.hosted-by.miamidedicated.com  (162.222.193.86:80)

TCP (HTTP):
Connects to server-54-192-55-55.jfk6.r.cloudfront.net  (54.192.55.55:80)

TCP (HTTP):
Connects to hosted-by.instantdedicated.com  (188.95.50.96:80)

TCP (HTTP):
Connects to eb.83.1732.ip4.static.sl-reverse.com  (50.23.131.235:80)

TCP (HTTP):
Connects to amung.us  (67.202.94.86:80)

TCP (HTTP):
Connects to 40.1e.2fa9.ip4.static.sl-reverse.com  (169.47.30.64:80)

Remove corrales.exe - Powered by Reason Core Security