lollipop_12141232.exe

The application lollipop_12141232.exe has been detected as a potentially unwanted program by 13 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘lollipop_12141232’. While running, it connects to the Internet address server-54-230-37-154.jfk1.r.cloudfront.net on port 80 using the HTTP protocol.
MD5:
14a98ca3056cd070061d6e6c7bdb1f65

SHA-1:
1e9e8e8d00cf2ee1ab9cf5a60f341fb1fc3e956d

SHA-256:
0130394dc34eb18e517f76f411dd0043b4680f40064879cb40321247a7ade290

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 11:13:35 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.A.2272
7.11.120.124

avast!
Win32:Adware-BHA [Adw]
2014.9-131222

AVG
Win32/Cryptor
2014.0.3618

Baidu Antivirus
Adware.Win32.Lollipop
4.0.3.131222

Emsisoft Anti-Malware
Gen:Variant.Adware.Lollipop
8.13.12.22.01

Fortinet FortiGate
W32/Skintrim.B!tr
12/22/2013

F-Secure
Gen:Variant.Adware.Lollipop.2
11.2013-22-12_1

G Data
Gen:Variant.Adware.Lollipop
13.12.22

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.2.29

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.4585

McAfee
Artemis!14A98CA3056C
5600.7274

Norman
Skintrim.PCK
11.20131222

Panda Antivirus
Suspicious file
13.12.22.01

File size:
3 MB (3,168,768 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\lollipop\lollipop_12141232.exe

File PE Metadata
Compilation timestamp:
9/4/2011 6:57:31 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:nMeeeeeJDX5spdRvpaCUg2qK19NeJYyxPLUe54SdYPltm1i1/LP7GYKUHGx+nV62:Meeeee1edtfQL

Entry address:
0x2FB9

Entry point:
E8, BC, 3D, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 4D, 08, 53, 33, DB, 56, 57, 3B, CB, 74, 07, 8B, 7D, 0C, 3B, FB, 77, 1B, E8, B7, 07, 00, 00, 6A, 16, 5E, 89, 30, 53, 53, 53, 53, 53, E8, 7B, F7, FF, FF, 83, C4, 14, 8B, C6, EB, 30, 8B, 75, 10, 3B, F3, 75, 04, 88, 19, EB, DA, 8B, D1, 8A, 06, 88, 02, 42, 46, 3A, C3, 74, 03, 4F, 75, F3, 3B, FB, 75, 10, 88, 19, E8, 7C, 07, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, C1, 33, C0, 5F, 5E, 5B, 5D, C3, 6A, 0C, 68, B0, 04, 41, 00, E8, 2D, 30, 00, 00, 83, 65...
 
[+]

Code size:
49 KB (50,176 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
lollipop_12141232

Command:
"C:\users\{user}\appdata\local\lollipop\lollipop_12141232.exe" lollipop_12141232


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to server-54-230-37-154.jfk1.r.cloudfront.net  (54.230.37.154:80)

Remove lollipop_12141232.exe - Powered by Reason Core Security