ctbe.exe

ClientConnect LTD

The file belongs to the ClientConnect (Conduit/Perion) platform, a utility that bundles and monetizes search toolbars and browser add-ons. The application ctbe.exe by ClientConnect has been detected as a potentially unwanted program by 4 anti-malware scanners. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from storage.conduit.com. While running, it connects to the Internet address cms.dmccint.com on port 80 using the HTTP protocol.
Publisher:
Conduit  (signed by ClientConnect LTD)

Version:
2.2.1.0

MD5:
0860692b23ec216ab14874598ca781c6

SHA-1:
23e2cabae1394d561566077a631a4fb92df75cf4

SHA-256:
85e22317ec5c9a30949abd658444d3f788e5746a1d1b65ad833033f47cc65b14

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Analysis date:
11/27/2024 12:27:58 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Conduit.45
9.0.1.075

Malwarebytes
PUP.Optional.Conduit.A
v2014.02.18.07

Reason Heuristics
PUP.ClientConnect.E
14.3.16.13

VIPRE Antivirus
Conduit
26612

File size:
78.7 KB (80,552 bytes)

Copyright:
Conduit Ltd.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ctbe.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/4/2014 2:00:00 AM

Valid to:
2/6/2016 1:59:59 AM

Subject:
CN=ClientConnect LTD, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Stub, O=ClientConnect LTD, L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
454C936FBC51DA40868FE2AB4727B946

File PE Metadata
Compilation timestamp:
2/24/2012 9:20:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:AGarUa6LowvuhdNYh2Gf9rg6hzGPnvCw1yf/1zZj5svPRSEvrG3:C5BuYAVrgUCPnvCf/1zZW5SEvrG3

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 84, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 18, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Entropy:
7.0828

Code size:
29 KB (29,696 bytes)

The file ctbe.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to cms.dmccint.com  (23.67.242.80:80)

 
http://cms.dmccint.com/DynamicOffer/2464665/2485788/?mainofferId=2461231&CurrentStep=2&TotalSteps=4&DownloadBrowser=IE&CType=-1&UserMode=-1&DMVersion=1.3.4.48.2484654.01&Language=US-EN

Remove ctbe.exe - Powered by Reason Core Security