disjoint.exe

Disjoint

The application disjoint.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named 38357259 triggered to execute each time a user logs in.
Publisher:
Disjoint

Product:
Disjoint

Version:
5.7.8.73

MD5:
e9a03ebd397484f02a7937a9922010fb

SHA-1:
f4c239a3588931279b071fa504808e25fb976558

SHA-256:
fda04c0312aeeb7fc082de216863791d581706e207f4ce7bd3f67ef2530a3da6

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 7:21:43 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/Adware.Dotdo.AP application
6.3.12010.0

Reason Heuristics
Adware.Dotdo.ET (M)
17.2.2.0

File size:
9 KB (9,216 bytes)

Product version:
5.7.8.73

Copyright:
Copyright © Disjoint 2017

Trademarks:
© 2017 Disjoint

Original file name:
disjoint.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\headquarter\disjoint.exe

File PE Metadata
Compilation timestamp:
1/31/2017 9:07:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x372E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.1914

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
6 KB (6,144 bytes)

Scheduled Task
Task name:
38357259

Trigger:
Logon (Runs on logon)

Description:
3835725938357259


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to hosted-by.instantdedicated.com  (188.95.50.96:80)

TCP (HTTP):
Connects to static.hosted-by.miamidedicated.com  (162.222.193.17:80)

TCP (HTTP):
Connects to server-54-230-141-148.sfo5.r.cloudfront.net  (54.230.141.148:80)

TCP (HTTP):
Connects to ec2-52-7-204-60.compute-1.amazonaws.com  (52.7.204.60:80)

TCP (HTTP):
Connects to cdce.dal003.internap.com  (74.201.53.198:80)

TCP (HTTP):
Connects to eb.83.1732.ip4.static.sl-reverse.com  (50.23.131.235:80)

TCP (HTTP):
Connects to lb-web.ustream.tv  (199.66.238.212:80)

TCP (HTTP):
Connects to server-52-84-63-87.ord51.r.cloudfront.net  (52.84.63.87:80)

TCP (HTTP):
Connects to amung.us  (67.202.94.93:80)

TCP (HTTP):
Connects to server-54-230-141-224.sfo5.r.cloudfront.net  (54.230.141.224:80)

TCP (HTTP):
Connects to server-52-85-77-217.lax3.r.cloudfront.net  (52.85.77.217:80)

TCP (HTTP):
Connects to server-52-84-246-180.sfo20.r.cloudfront.net  (52.84.246.180:80)

TCP (HTTP):
Connects to ec2-107-23-223-146.compute-1.amazonaws.com  (107.23.223.146:80)

TCP (HTTP):
Connects to cdce.nym011.internap.com  (63.251.19.8:80)

TCP (HTTP):
Connects to cdce.acs006.internap.com  (64.74.126.12:80)

Remove disjoint.exe - Powered by Reason Core Security