lollipop_03280255.exe

vitriolerai

Sonny

The application lollipop_03280255.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘lollipop_03280255’.
Publisher:
Sonny

Product:
vitriolerai

Description:
novelize

Version:
9, 7, 8, 5

MD5:
33acd61cd413f7160b63c02dcf6fd02f

SHA-1:
7d85918958b30bbd8bd7195424fcfab49b556e32

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/8/2024 8:50:40 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Lollipop (M)
16.8.3.18

File size:
3.3 MB (3,444,224 bytes)

Product version:
9, 7, 8, 5

Copyright:
soigne

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Application data\lollipop\lollipop_03280255.exe

File PE Metadata
Compilation timestamp:
2/15/2014 2:25:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:RCsssssLBb+DBbxXW6QD/ejonMO9TDz4mtIHufk47ARvMoA0DdeoFBFbvsIhfgcg:R8

Entry address:
0x2BFA

Entry point:
55, 8B, EC, 6A, FF, 68, B8, F2, 73, 00, 68, 86, 2D, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, A0, 50, 73, 00, 59, 83, 0D, C4, A3, 74, 00, FF, 83, 0D, C8, A3, 74, 00, FF, FF, 15, 74, 50, 73, 00, 8B, 0D, BC, A3, 74, 00, 89, 08, FF, 15, 70, 50, 73, 00, 8B, 0D, B8, A3, 74, 00, 89, 08, A1, 64, 50, 73, 00, 8B, 00, A3, C0, A3, 74, 00, E8, 1C, 01, 00, 00, 39, 1D, C0, A2, 74, 00, 75, 0C, 68, 82, 2D, 40, 00, FF, 15, 58, 50...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
3.2 MB (3,356,160 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
lollipop_03280255

Command:
"C:\Documents and Settings\{user}\Application data\lollipop\lollipop_03280255.exe" lollipop_03280255


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to w01.lopn.eu  (5.39.47.211:80)

TCP (HTTP):
Connects to ec2-54-244-234-44.us-west-2.compute.amazonaws.com  (54.244.234.44:80)

TCP (HTTP):
Connects to ec2-54-217-211-214.eu-west-1.compute.amazonaws.com  (54.217.211.214:80)

TCP (HTTP):
Connects to ec2-107-23-147-63.compute-1.amazonaws.com  (107.23.147.63:80)

TCP (HTTP):
Connects to ec2-107-22-213-140.compute-1.amazonaws.com  (107.22.213.140:80)

Remove lollipop_03280255.exe - Powered by Reason Core Security