PennyBeeW.exe

PennyBee

MY POP SHOP LTD

The application PennyBeeW.exe by MY POP SHOP has been detected as adware by 5 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PennyBee’. While running, it connects to the Internet address blob.am5prdstr07a.store.core.windows.net on port 80 using the HTTP protocol.
Publisher:
MY POP SHOP LTD  (signed and verified)

Product:
PennyBee

Version:
1.0.3.0

MD5:
35831338bf0b679c51059673249730ec

SHA-1:
954ad0b60a47178270478c8d81487e0253b8575a

SHA-256:
edc5b33872641036bdf097e2b95c78cb9597233a7f6dbd1dad701d9dd700791a

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
11/23/2024 2:26:36 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Mypopshop
2015.0.3348

Baidu Antivirus
PUA.MSIL.Linkury
4.0.3.14917

ESET NOD32
MSIL/Toolbar.Linkury (variant)
8.10434

McAfee
Artemis!35831338BF0B
5600.7004

Reason Heuristics
PUP.Startup.MYPOPSHOP.J
14.9.17.21

File size:
337 KB (345,096 bytes)

Product version:
1.0.3.0

Copyright:
Copyright © 2014

Original file name:
PennyBeeW.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\pennybee\pennybeew.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/21/2014 8:00:00 PM

Valid to:
7/22/2015 7:59:59 PM

Subject:
CN=MY POP SHOP LTD, O=MY POP SHOP LTD, STREET=14 Shenkar Arie, L=HERZLIYA, S=NA, PostalCode=46725, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B739C4F756EE55FB750952CE570BE48B

File PE Metadata
Compilation timestamp:
9/17/2014 3:38:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:HxfLdaZIVOyAhpjfco5g8GvCHTtFFmkf4UyChATR0KCY57c:R5OyIfco5a6JF/DKTmk7c

Entry address:
0x4BEBE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
296 KB (303,104 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PennyBee

Command:
C:\users\{user}\appdata\local\pennybee\pennybeew.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to blob.am5prdstr07a.store.core.windows.net  (13.95.96.184:80)

TCP (HTTP):
Connects to yyz08s13-in-f20.1e100.net  (74.125.226.116:80)

Remove PennyBeeW.exe - Powered by Reason Core Security