limewire-music-free.exe

LimeWire Music

Prospera Software, Inc.

The application limewire-music-free.exe by Prospera Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from pronetsharing.s3.amazonaws.com. While running, it connects to the Internet address f2.fd.adb8.ip4.static.sl-reverse.com on port 80 using the HTTP protocol.
Publisher:
ProNetSharing LLC  (signed by Prospera Software, Inc.)

Product:
LimeWire Music

Version:
5.6.0.0

MD5:
27d8ff3798d823c7ba1b10ed6e27fd42

SHA-1:
4b5d0ea4fd25abf089ac14246ca604a683c3d657

SHA-256:
769a4fc43ac65966944c9beb19e85d37ee3754aa1ee92ceedfa81bd1bc62d3e1

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
2/24/2025 7:16:35 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ProsperaSoftware.Installer (M)
15.12.9.18

File size:
5 MB (5,269,200 bytes)

Copyright:
� ProNetSharing LLC

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\limewire-music-free.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/25/2015 2:00:00 AM

Valid to:
5/25/2016 1:59:59 AM

Subject:
CN="Prospera Software, Inc.", O="Prospera Software, Inc.", POBox=30024, STREET=4539 Arbor Crest Place, L=Suwanee, S=Georgia, PostalCode=30024, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
19A1AE80173FC78EF95D67C4BB75F591

File PE Metadata
Compilation timestamp:
2/24/2012 8:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:oNfIX444YhKofpmZRKTLSOpFvVQqsAaC9n1udwq18NAB:oNQXZXfficFvGqsFC9nY318c

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file limewire-music-free.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to f2.fd.adb8.ip4.static.sl-reverse.com  (184.173.253.242:80)

TCP (HTTP):
Connects to 14.d7.24ae.ip4.static.sl-reverse.com  (174.36.215.20:80)

Remove limewire-music-free.exe - Powered by Reason Core Security