FreeWebsiteBuilder.exe

Free Website Builder

Media Freeware

The application FreeWebsiteBuilder.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address ip-184-168-221-1.ip.secureserver.net on port 80 using the HTTP protocol.
Publisher:
Media Freeware

Product:
Free Website Builder

Version:
1.0.0.0

MD5:
72f8b14196f00c20e7f79a9f7b674564

SHA-1:
739a6c200e67e7e1247158360bb4a5960c9ea53b

SHA-256:
540109085ae281ff779e1875d7a915c9b2a3ce2eb7f78693e05178b348a05dd7

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 4:37:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.1.2.13

File size:
1.5 MB (1,577,472 bytes)

Product version:
1.0.0.0

Copyright:
Media Freeware

Original file name:
FreeWebsiteBuilder.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\media freeware\free website builder\freewebsitebuilder.exe

File PE Metadata
Compilation timestamp:
3/31/2014 7:18:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:gS1d1c1Y8731c1c1c1c1c1c1s1c1W1v1c1c1ERb3Fkmw01:JnuV73uuuuuu2uEFuuSb3Fkmw0

Entry address:
0x171F1E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5224

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.4 MB (1,507,328 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ip-50-63-202-25.ip.secureserver.net  (50.63.202.25:80)

TCP (HTTP):
Connects to ip-50-63-202-11.ip.secureserver.net  (50.63.202.11:80)

TCP (HTTP):
Connects to ip-184-168-221-1.ip.secureserver.net  (184.168.221.1:80)

TCP (HTTP):
Connects to 23-111-140-234.static.hvvc.us  (23.111.140.234:80)

Remove FreeWebsiteBuilder.exe - Powered by Reason Core Security