DTLite.exe

DAEMON TOOLS LITE

EbizNetWorks

The application DTLite.exe by EbizNetWorks has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address disc-soft.com on port 443.
Publisher:
(주)이비즈네트웍스  (signed by EbizNetWorks)

Product:
DAEMON TOOLS LITE

Version:
5.661.0.3

MD5:
0d72a761961f91de14669a37ec437fd3

SHA-1:
7b11034dbb2ae180de3e7068739edc7fde2a9b17

SHA-256:
3986439566f2dde311f4a44c84b33b38c34d75b0c102f5d705f0d2727af803e9

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/24/2024 1:56:58 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.9.12

File size:
4.5 MB (4,758,408 bytes)

Product version:
5.661.0.3

Copyright:
(c) <EbizNetWorks>. All rights reserved.

Original file name:
DTLite.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\daemon tools lite\dtlite.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
4/28/2016 9:00:00 AM

Valid to:
1/23/2018 8:59:59 AM

Subject:
CN=EbizNetWorks, O=EbizNetWorks, L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
6EAD56FB10FC05615CA954D77165999F

File PE Metadata
Compilation timestamp:
2/8/2017 8:22:07 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x16DE34

Entry point:
48, 83, EC, 28, E8, 83, A5, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 48, 8B, C1, 0F, B7, 10, 48, 83, C0, 02, 66, 85, D2, 75, F4, 48, 2B, C1, 48, D1, F8, 48, FF, C8, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 8B, C1, 48, F7, D9, 48, A9, 07, 00, 00, 00, 74, 0F, 66, 90, 8A, 10, 48, FF, C0, 84, D2, 74, 5F, A8, 07, 75, F3, 49, B8, FF, FE, FE, FE, FE, FE, FE, 7E, 49, BB, 00, 01, 01, 01, 01, 01, 01, 81, 48, 8B, 10...
 
[+]

Entropy:
6.0911

Code size:
1.6 MB (1,655,296 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ip-static-94-242-254-192.server.lu  (94.242.254.192:80)

TCP (HTTP SSL):
Connects to disc-soft.com  (217.147.90.28:443)

TCP (HTTP):
Connects to mail.duplexsecure.com  (212.117.175.144:80)

Remove DTLite.exe - Powered by Reason Core Security