csrcc.exe

TODO:

Acai Tech Ltd

The application csrcc.exe, “TODO: <File description>” by Acai Tech has been detected as adware by 12 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “csrcc”. While running, it connects to the Internet address server-54-192-91-26.ind6.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
TODO: <Company name>  (signed by Acai Tech Ltd)

Product:
TODO: <Product name>

Description:
TODO: <File description>

Version:
1.0.0.1

MD5:
af67710d87cb83edf65da4d078a69afe

SHA-1:
c3ccd358bc2d81e8de16c5616696a6d1ae72a15f

SHA-256:
f5fb039a0a67e32e3278f2f07005cc67788adbc025f541c111d4985b62c96f05

Scanner detections:
12 / 68

Status:
Adware

Analysis date:
12/28/2024 11:51:12 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Kazy.435629
780

Bitdefender
Gen:Variant.Adware.Kazy.435629
1.0.20.1750

Emsisoft Anti-Malware
Gen:Variant.Adware.Kazy.435629
8.14.12.16.02

ESET NOD32
Win32/Toolbar.Perion (variant)
8.10876

F-Secure
Gen:Variant.Adware.Kazy.435629
11.2014-16-12_3

G Data
Gen:Variant.Adware.Kazy.435629
14.12.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.5.0

Malwarebytes
PUP.Optional.Perion
v2014.12.16.02

MicroWorld eScan
Gen:Variant.Adware.Kazy.435629
15.0.0.1050

Reason Heuristics
PUP.Service.AcaiTech.F
14.12.16.13

Trend Micro House Call
TROJ_GEN.R047H09L214
7.2.350

VIPRE Antivirus
Trojan.Win32.Generic
35728

File size:
301.8 KB (309,048 bytes)

Product version:
1.0.0.1

Copyright:
TODO: (c) <Company name>. All rights reserved.

Original file name:
csrcc.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\shop for rewards\csrcc.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/21/2014 8:00:00 PM

Valid to:
9/22/2015 7:59:59 PM

Subject:
CN=Acai Tech Ltd, O=Acai Tech Ltd, STREET=Rakefet 19, L=Hod Hasharon, S=Sharon, PostalCode=4520634, C=IL

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
189E85B982528243713729AC8244D22C

File PE Metadata
Compilation timestamp:
11/26/2014 10:34:19 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:MNjgfnyJKWSxIAuFWIrZVDPSi/yKwi4cVpaaD7M8aZ+S0YuaciPOuVgenqjE:MCfyoHuFbuKw4WQOO0qQ

Entry address:
0x197D4

Entry point:
E8, C8, 65, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 40, A1, 43, 00, E8, 96, 02, 00, 00, E8, 5E, 08, 00, 00, 0F, B7, F0, 6A, 02, E8, 5B, 65, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 28, 0C, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
5.9596

Code size:
186 KB (190,464 bytes)

Service
Display name:
csrcc

Type:
Win32OwnProcess

Depends on:
RPCSS


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to server-54-192-91-26.ind6.r.cloudfront.net  (54.192.91.26:80)

Remove csrcc.exe - Powered by Reason Core Security