DTLite.exe

DAEMON TOOLS LITE

EbizNetWorks

The application DTLite.exe by EbizNetWorks has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address ip-static-94-242-254-192.server.lu on port 80 using the HTTP protocol.
Publisher:
(주)이비즈네트웍스  (signed by EbizNetWorks)

Product:
DAEMON TOOLS LITE

Version:
5.661.0.3

MD5:
e426c80b7ad3292c00533648f70c70a2

SHA-1:
4173bc5a3cf760ff6a045cec8e4e03f8f9a308e9

SHA-256:
dc2e27ba0596b95648bd31664578584b13888153d8400940c7b9f12742062646

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 12:41:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.5.12

File size:
4.5 MB (4,758,408 bytes)

Product version:
5.661.0.3

Copyright:
(c) <EbizNetWorks>. All rights reserved.

Original file name:
DTLite.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\daemon tools lite\dtlite.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
4/28/2016 9:00:00 AM

Valid to:
1/23/2018 8:59:59 AM

Subject:
CN=EbizNetWorks, O=EbizNetWorks, L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
6EAD56FB10FC05615CA954D77165999F

File PE Metadata
Compilation timestamp:
1/5/2017 6:11:04 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x16DE34

Entry point:
48, 83, EC, 28, E8, 83, A5, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 48, 8B, C1, 0F, B7, 10, 48, 83, C0, 02, 66, 85, D2, 75, F4, 48, 2B, C1, 48, D1, F8, 48, FF, C8, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 8B, C1, 48, F7, D9, 48, A9, 07, 00, 00, 00, 74, 0F, 66, 90, 8A, 10, 48, FF, C0, 84, D2, 74, 5F, A8, 07, 75, F3, 49, B8, FF, FE, FE, FE, FE, FE, FE, 7E, 49, BB, 00, 01, 01, 01, 01, 01, 01, 81, 48, 8B, 10...
 
[+]

Entropy:
6.0942

Code size:
1.6 MB (1,655,296 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ip-static-94-242-254-192.server.lu  (94.242.254.192:80)

TCP (HTTP SSL):
Connects to cache.google.com  (59.18.44.217:443)

TCP (HTTP SSL):
Connects to tl-in-f105.1e100.net  (64.233.189.105:443)

TCP (HTTP SSL):
Connects to tk-in-f155.1e100.net  (64.233.188.155:443)

TCP (HTTP):
Connects to nrt13s51-in-f10.1e100.net  (172.217.25.106:80)

TCP (HTTP SSL):
Connects to nrt13s51-in-f1.1e100.net  (172.217.25.97:443)

TCP (HTTP SSL):
Connects to nrt13s49-in-f226.1e100.net  (216.58.197.226:443)

TCP (HTTP):
Connects to nrt13s49-in-f10.1e100.net  (216.58.197.234:80)

TCP (HTTP):
Connects to nrt12s14-in-f10.1e100.net  (172.217.25.234:80)

TCP (HTTP SSL):
Connects to nrt12s11-in-f162.1e100.net  (216.58.200.162:443)

TCP (HTTP SSL):
Connects to nrt12s02-in-f2.1e100.net  (216.58.197.162:443)

TCP (HTTP SSL):
Connects to hkg12s11-in-f2.1e100.net  (216.58.200.2:443)

TCP (HTTP SSL):
Connects to hkg07s23-in-f4.1e100.net  (172.217.24.36:443)

TCP (HTTP SSL):
Connects to hkg07s02-in-f2.1e100.net  (216.58.221.130:443)

TCP (HTTP SSL):
Connects to hkg07s02-in-f129.1e100.net  (216.58.221.129:443)

TCP (HTTP):
Connects to a203-13-161-139.deploy.akamaitechnologies.com  (203.13.161.139:80)

TCP (HTTP SSL):
Connects to a104-98-244-204.deploy.static.akamaitechnologies.com  (104.98.244.204:443)

Remove DTLite.exe - Powered by Reason Core Security