CureTraffic.exe

CureTraffic

Vitbian telecom sl

The application CureTraffic.exe by Vitbian telecom sl has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘CureTraffic’.
Publisher:
Vitbian telecom S.L  (signed by Vitbian telecom sl)

Product:
CureTraffic

Version:
1.0.0.7

MD5:
c79ba30055a34f4f7f322a4d4dc2d7f6

SHA-1:
401f615c73db6d84dc4fa12bd75f00e0f73951a9

SHA-256:
075dc522127ed62457871ddfa85a69e2715d64f15ef5aa4ce6dd92da0a569b7e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/23/2024 7:23:03 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Vitbiant (M)
16.4.3.12

File size:
750.9 KB (768,872 bytes)

Product version:
1.0.0.7

Copyright:
Copyright © 2013

Original file name:
CureTraffic.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\curetraffic\curetraffic.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/1/2013 1:00:00 AM

Valid to:
2/2/2014 12:59:59 AM

Subject:
CN=Vitbian telecom sl, O=Vitbian telecom sl, STREET=calle durango 45, L=madrid, S=madrid, PostalCode=28023, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2B1E042090F8B8A605FB4A8E606FAF59

File PE Metadata
Compilation timestamp:
5/2/2013 6:03:11 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:mxZPUeB/OVBh4N8YA4N8YTgq1G4N8YZzjlKFeEFVE4N8Y84N84g:mxZP9OVBh4NxA4NxTN1G4Nxp084Nx84k

Entry address:
0xA98FE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
670.5 KB (686,592 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
CureTraffic

Command:
"C:\Program Files\curetraffic\curetraffic.exe"


Remove CureTraffic.exe - Powered by Reason Core Security