ed155d7b-faa8-4fca-8603-de29b2bec179-10_iobitdel.exe

Ge-Force

Webar

The application ed155d7b-faa8-4fca-8603-de29b2bec179-10_iobitdel.exe has been detected as adware by 18 anti-malware scanners. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. While running, it connects to the Internet address ip-50-63-202-62.ip.secureserver.net on port 80 using the HTTP protocol.
Publisher:
Webar

Product:
Ge-Force

Description:
Ge-Force exe

Version:
1000.1000.1000.1000

MD5:
32e77f591908aa0bf7c90429a2cf418c

SHA-1:
ecef36cf9d15973c0e7ac9a99556b98efebe031f

SHA-256:
1ffc1f092b328588bbbae27ebc357e5add2f17ff1ffad53058e87aeda4bd511c

Scanner detections:
18 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
12/4/2024 6:42:08 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.171733
638

Avira AntiVirus
ADWARE/CrossRider.Gen7
8.3.1.6

avast!
Win32:Adware-CMH [PUP]
2014.9-150508

AVG
Adware Generic_r
2016.0.3116

Baidu Antivirus
Adware.Win32.CrossAd
4.0.3.1558

Bitdefender
Gen:Variant.Adware.Graftor.171733
1.0.20.640

Dr.Web
Trojan.Crossrider1.29470
9.0.1.0185

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.171733
8.15.05.08.08

ESET NOD32
Win32/Toolbar.CrossRider.CD potentially unwanted application
9.7.0.302.0

F-Secure
Gen:Variant.Adware.Graftor
11.2015-08-05_6

G Data
Gen:Variant.Adware.Graftor.171733
15.5.25

Malwarebytes
PUP.Optional.CrossRider
v2015.05.08.08

MicroWorld eScan
Gen:Variant.Adware.Graftor.171733
16.0.0.384

Reason Heuristics
Adware.Crossrider.Webar
15.5.8.4

Sophos
AppRider
4.98

SUPERAntiSpyware
Adware.CrossRider/Variant
9888

VIPRE Antivirus
Trojan.Win32.Generic
41492

File size:
1.4 MB (1,501,696 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Ge-Force.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ge-force\ed155d7b-faa8-4fca-8603-de29b2bec179-10_iobitdel.exe

File PE Metadata
Compilation timestamp:
5/7/2015 6:06:31 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:OGz3HrXBnB23c5cs04ivm2IQG8Xx4Z57rDVkxCf6cxi+78i8X7ATXpSxBzm9UKFT:OQ3HrXBnboemUDcCfV38X8TXpSx9fK4C

Entry address:
0xC404D

Entry point:
E8, 3B, FE, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 58, F9, 54, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 58, C1, 54, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 58, F9, 54, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8...
 
[+]

Code size:
980 KB (1,003,520 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-23-21-185-158.compute-1.amazonaws.com  (23.21.185.158:80)

TCP (HTTP):
Connects to ec2-50-17-240-68.compute-1.amazonaws.com  (50.17.240.68:80)

TCP (HTTP):
Connects to ip-50-63-202-62.ip.secureserver.net  (50.63.202.62:80)

TCP (HTTP):
Connects to ec2-107-20-224-23.compute-1.amazonaws.com  (107.20.224.23:80)

TCP (HTTP):
Connects to ec2-50-17-200-93.compute-1.amazonaws.com  (50.17.200.93:80)

TCP (HTTP):
Connects to ec2-23-23-100-24.compute-1.amazonaws.com  (23.23.100.24:80)

TCP (HTTP):
Connects to ec2-174-129-43-250.compute-1.amazonaws.com  (174.129.43.250:80)

TCP (HTTP):
Connects to ec2-23-23-114-129.compute-1.amazonaws.com  (23.23.114.129:80)

TCP (HTTP):
Connects to s3-website-us-east-1.amazonaws.com  (54.231.120.153:80)

TCP (HTTP):
Connects to ec2-54-243-91-79.compute-1.amazonaws.com  (54.243.91.79:80)

TCP (HTTP):
Connects to ec2-54-227-241-50.compute-1.amazonaws.com  (54.227.241.50:80)

TCP (HTTP):
Connects to ec2-54-225-64-6.compute-1.amazonaws.com  (54.225.64.6:80)

TCP (HTTP):
Connects to ec2-54-225-240-148.compute-1.amazonaws.com  (54.225.240.148:80)

TCP (HTTP):
Connects to ec2-54-221-207-153.compute-1.amazonaws.com  (54.221.207.153:80)

TCP (HTTP):
Connects to ec2-50-16-193-32.compute-1.amazonaws.com  (50.16.193.32:80)

TCP (HTTP):
Connects to ec2-23-21-50-56.compute-1.amazonaws.com  (23.21.50.56:80)