emuletorrent.exe

ROMEO SOUTH SL

The application emuletorrent.exe by ROMEO SOUTH SL has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program eMuleTorrent by eMule.com. While running, it connects to the Internet address 198-84-162-12.cpe.teksavvy.com on port 58530.
Publisher:
ROMEO SOUTH SL  (signed and verified)

MD5:
17ba52b1a0b08255432523ff95d1ab3e

SHA-1:
d94ff973bf049fca12a0caf224d0edd8b05bca7c

SHA-256:
0b4cc9d420e9ef8cc0c68292ab8a88bc2b6848ed849a99edbbce069e2e027d12

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 3:52:50 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Vitallia.ROMEOSOU (M)
16.4.21.14

File size:
8.6 MB (8,969,936 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\emuletorrent\emuletorrent.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
2/2/2016 8:54:38 AM

Valid to:
6/19/2016 7:09:57 AM

Subject:
CN=ROMEO SOUTH SL, O=ROMEO SOUTH SL, L=Madrid, S=Madrid, C=ES

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B7E997895C66952

File PE Metadata
Compilation timestamp:
3/13/2016 10:32:44 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:J2E8SbgmVJtut86MZZJ7XYgAe4+YfFjSRRAfMWnj412YLQgQxAPF/wVPmA/yI78L:JhngmV/089x7XYgA7FjXYiNaILLzO

Entry address:
0x38D6C0

Entry point:
E8, 83, 07, 00, 00, E9, 36, FD, FF, FF, 8B, FF, 55, 8B, EC, FF, 75, 08, E8, A5, F8, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 5D, E9, 1B, FB, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 55, 33, FF, 33, ED, 8B, 44, 24, 14, 0B, C0, 7D, 15, 47, 45, 8B, 54, 24, 10, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 14, 89, 54, 24, 10, 8B, 44, 24, 1C, 0B, C0, 7D, 14, 47, 8B, 54, 24, 18, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 1C, 89, 54, 24, 18, 0B, C0, 75, 28, 8B, 4C, 24, 18, 8B, 44, 24, 14, 33, D2, F7, F1...
 
[+]

Code size:
4 MB (4,232,192 bytes)

Windows Firewall Allowed Program
Name:
emuletorrent


The file emuletorrent.exe has been discovered within the following program.

eMuleTorrent  by eMule.com
www.emule.com
About 5% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ns348787.ip-94-23-32.eu  (94.23.32.125:80)

TCP:
Connects to node45.hvosting.ua  (91.200.42.46:1176)

TCP (HTTP):
Connects to ns373675.ip-94-23-250.eu  (94.23.250.171:80)

TCP:
Connects to vodsl-8222.vo.lu  (85.93.199.30:4662)

TCP:
Connects to mail.zavodchzem.ru  (62.176.25.14:40154)

TCP:
Connects to ip123-148.telenet.dn.ua  (178.216.123.148:64088)

TCP:
Connects to dynamic-cpe-pool.callplus.net.nz  (101.98.152.155:63393)

TCP:
Connects to client-adsl-93-121-138-253.mediaserv.net  (93.121.138.253:53376)

TCP:
Connects to catv-89-132-66-148.catv.broadband.hu  (89.132.66.148:56897)

TCP (HTTP):
Connects to boieroom.org  (141.255.161.22:80)

TCP:
Connects to bband-dyn172.178-40-46.t-com.sk  (178.40.46.172:54618)

TCP:
Connects to bb116-14-206-96.singnet.com.sg  (116.14.206.96:60989)

TCP:
Connects to b122c546.virtua.com.br  (177.34.197.70:51981)

TCP:
Connects to 81-67-213-68.rev.numericable.fr  (81.67.213.68:32500)

TCP:
Connects to 79-117-253-232.rdsnet.ro  (79.117.253.232:61090)

TCP:
Connects to 77-253-156-113.adsl.inetia.pl  (77.253.156.113:58581)

TCP:
Connects to 69-16-147-148.ipvanish.com  (69.16.147.148:64031)

TCP:
Connects to 4-148-255-141.dynip.ipjetable.net  (141.255.148.4:62327)

TCP:
Connects to 216.21.32.95.dsl-dynamic.vsi.ru  (95.32.21.216:24572)

TCP:
Connects to 198-84-162-12.cpe.teksavvy.com  (198.84.162.12:58530)

Remove emuletorrent.exe - Powered by Reason Core Security