mydesk.exe

软媒桌面

Qingdao Ruanmei Network Technology Co.,Ltd.

The application mydesk.exe by Qingdao Ruanmei Network Technology Co.,Ltd has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address pc-b.bitgravity.com on port 80 using the HTTP protocol.
Publisher:
青岛软媒网络科技有限公司  (signed by Qingdao Ruanmei Network Technology Co.,Ltd.)

Product:
软媒桌面

Version:
1.0.3.0

MD5:
b58f63b1f634408ed205c871bef72d23

SHA-1:
bb373a60b3d1784f5f7b8e7851e66dedc475c6e7

SHA-256:
ff270559cf0266e5bda47b66ce19b86dacba69047115eeda8b006bb55db41fd1

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 10:16:12 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.11.22.19

File size:
3.1 MB (3,273,072 bytes)

Product version:
1.0.3.0

Copyright:
青岛软媒

Original file name:
mydesk.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ruanmei\pcmaster\mydesk.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/25/2014 8:00:00 AM

Valid to:
8/24/2017 7:59:59 AM

Subject:
CN="Qingdao Ruanmei Network Technology Co.,Ltd.", OU=IT, O="Qingdao Ruanmei Network Technology Co.,Ltd.", L=Qingdao, S=Shandong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
41E4F3478CEB8F3B8B87E0AB04A7ACCF

File PE Metadata
Compilation timestamp:
8/30/2014 9:32:02 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:Fd33Wdz83+d6QRwWT7c8KF+agaKMTzgNJ+t/q3iKX/NOg6:Fd33Mz83+d6QRwWT7c8KF+agaKMTzgbq

Entry address:
0x199653

Entry point:
E8, 76, 5E, 01, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, B8, 20, 10, 00, 00, E8, 44, C4, FF, FF, A1, A0, 62, 62, 00, 33, C5, 89, 45, FC, 53, 56, 8B, 75, 08, 57, 56, E8, 9C, 40, 00, 00, 8B, D8, 33, C0, 59, 89, 9D, E8, EF, FF, FF, 39, 46, 04, 7D, 03, 89, 46, 04, 6A, 01, 50, 50, 53, E8, 4F, 5F, 01, 00, 83, C4, 10, 8B, F8, 89, BD, EC, EF, FF, FF, 89, 95, F0, EF, FF, FF, 85, D2, 7F, 10, 7C, 04, 85, FF, 73, 0A, 83, C8, FF, 0B, D0, E9, D4, 02, 00, 00, 8B, C3, C1, F8, 05, 8D, 04, 85, 20, BE, 62, 00, 83, E3, 1F...
 
[+]

Entropy:
7.0159

Code size:
1.8 MB (1,855,488 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to pc-b.bitgravity.com  (64.185.181.238:80)

Remove mydesk.exe - Powered by Reason Core Security