lemurleapun.exe

LemurLeap

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application lemurleapun.exe by LemurLeap has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is the uninstaller utility registered in the Windows Control Panel for the program LemurLeap 1.0.0 by LemurLeap. While running, it connects to the Internet address install.lemurleap.info on port 80 using the HTTP protocol.
Publisher:
LemurLeap  (signed and verified)

Version:
1.0.0.0

MD5:
16934296c6dfdc86aaa100303dc5aac0

SHA-1:
6d7455ca0e3dbddcd35dbc0e4c27c1abd32b2be2

SHA-256:
9290f72db5f531ff3e67e0ae497f2c9496416e8a06ae0afb7ff19f5186373bd0

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Belongs to the Sambreel/Yontoo progam that inserts various forms of advertising in the user's web browser, installed with minimal or no user consent.

Analysis date:
12/23/2024 5:07:09 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo (M)
17.3.2.20

File size:
539.3 KB (552,224 bytes)

Product version:
1.0.0.0

Original file name:
LemurLeap Uninstaller.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\lemurleap\lemurleapun.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/13/2013 3:00:00 AM

Valid to:
8/14/2015 2:59:59 AM

Subject:
CN=LemurLeap, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=LemurLeap, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
59846B2F05AAAD396A7E942BF33F16B3

File PE Metadata
Compilation timestamp:
8/8/2015 6:03:58 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x84CF3

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.1291

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
523.5 KB (536,064 bytes)

Program Uninstaller
Program name:
LemurLeap 1.0.0

Display publisher:
LemurLeap

Display version:
1.0.0

Uninstall string:
C:\Program Files\LemurLeap\LemurLeapUn.exe OFS_


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to wpc.0952.edgecastcdn.net  (68.232.34.163:80)

TCP (HTTP):
Connects to install.lemurleap.info  (70.186.131.186:80)

Remove lemurleapun.exe - Powered by Reason Core Security