DTLite.exe

DAEMON TOOLS LITE

EbizNetWorks

The application DTLite.exe by EbizNetWorks has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address v3.kornu.ac.kr on port 80 using the HTTP protocol.
Publisher:
(주)이비즈네트웍스  (signed by EbizNetWorks)

Product:
DAEMON TOOLS LITE

Version:
5.661.0.3

MD5:
180eb98f4920f87c8c0336af1478452b

SHA-1:
5d77b13392b91ebff76c493cbc8e1f68b5f53d9b

SHA-256:
9e0e9dd6a72b1287270e32f56af7218afb7123d3219e4fe27c56ca69cd357bf9

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 12:36:29 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.11.17.10

File size:
4.5 MB (4,758,408 bytes)

Product version:
5.661.0.3

Copyright:
(c) <EbizNetWorks>. All rights reserved.

Original file name:
DTLite.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\daemon tools lite\dtlite.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
4/28/2016 9:00:00 AM

Valid to:
1/23/2018 8:59:59 AM

Subject:
CN=EbizNetWorks, O=EbizNetWorks, L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
6EAD56FB10FC05615CA954D77165999F

File PE Metadata
Compilation timestamp:
11/17/2016 9:05:08 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:A49Y9Shz0bTG+JGkkxpc2BnqvYd4bdd38dOcAijbffdiwGBpz2BG:UShkwc2Bnqb2BG

Entry address:
0x16DE34

Entry point:
48, 83, EC, 28, E8, 83, A5, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 48, 8B, C1, 0F, B7, 10, 48, 83, C0, 02, 66, 85, D2, 75, F4, 48, 2B, C1, 48, D1, F8, 48, FF, C8, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 8B, C1, 48, F7, D9, 48, A9, 07, 00, 00, 00, 74, 0F, 66, 90, 8A, 10, 48, FF, C0, 84, D2, 74, 5F, A8, 07, 75, F3, 49, B8, FF, FE, FE, FE, FE, FE, FE, 7E, 49, BB, 00, 01, 01, 01, 01, 01, 01, 81, 48, 8B, 10...
 
[+]

Entropy:
6.0942

Code size:
1.6 MB (1,655,296 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ip-static-94-242-254-192.server.lu  (94.242.254.192:80)

TCP (HTTP SSL):
Connects to disc-soft.com  (217.147.90.28:443)

TCP (HTTP):
Connects to v3.kornu.ac.kr  (116.68.32.69:80)

Remove DTLite.exe - Powered by Reason Core Security