safeup.exe

OPTI ADS LTD

The application safeup.exe by OPTI ADS has been detected as a potentially unwanted program by 16 anti-malware scanners. While running, it connects to the Internet address ny1wv3280.xglobe.net on port 80 using the HTTP protocol.
Publisher:
OPTI ADS LTD  (signed and verified)

Version:
1.3.0.0

MD5:
6934178da8629a39538369071be64d9f

SHA-1:
60e4037677d477a4f80eeecb4dd39983c683de8e

SHA-256:
b55fa10e9fc9c8b49e081eeac0cce2cb1c20a2342e9c5a5b99454a307e3b0664

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
11/18/2024 5:18:26 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/Montiera.Gen7
8.3.1.6

Baidu Antivirus
PUA.Win32.Montiera
4.0.3.15820

Bkav FE
W32.HfsAdware
1.3.0.7062

Dr.Web
Adware.Toolbar.694
9.0.1.0232

ESET NOD32
Win32/Toolbar.Montiera.R potentially unwanted (variant)
9.12082

Fortinet FortiGate
Riskware/Montiera
8/20/2015

IKARUS anti.virus
PUA.Toolbar.Montiera
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.208.16862

Kaspersky
not-a-virus:Downloader.Win32.Montiera
14.0.0.1544

Malwarebytes
PUP.Optional.OptiAds.A
v2015.08.20.03

McAfee
Artemis!6934178DA862
5600.6667

NANO AntiVirus
Riskware.Win32.Toolbar.duxmew
0.30.24.3079

Qihoo 360 Security
Win32/Virus.a00
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.8.21.22

Sophos
Generic PUA GA (PUA)
4.98

VIPRE Antivirus
Trojan.Win32.Generic
42830

File size:
446.4 KB (457,120 bytes)

Copyright:
All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\delta\delta\1.3.28.0\safeup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
3/13/2015 1:00:00 AM

Valid to:
3/23/2016 1:00:00 PM

Subject:
CN=OPTI ADS LTD, O=OPTI ADS LTD, L=Tel Aviv, S=Tel Aviv, C=IL

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
019E7E421DD92BB6922755CD51B3A65C

File PE Metadata
Compilation timestamp:
8/2/2015 5:54:43 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:H8FktQNP6uDYD9man/M7XGAmODETuR8KGEOXpZbP:cp6UXbmODETYGE6Zj

Entry address:
0x37C4A

Entry point:
E8, 63, 84, 00, 00, E9, 89, FE, FF, FF, B8, F7, 0B, 44, 00, A3, 30, 54, 46, 00, C7, 05, 34, 54, 46, 00, ED, 02, 44, 00, C7, 05, 38, 54, 46, 00, A1, 02, 44, 00, C7, 05, 3C, 54, 46, 00, DA, 02, 44, 00, C7, 05, 40, 54, 46, 00, 43, 02, 44, 00, A3, 44, 54, 46, 00, C7, 05, 48, 54, 46, 00, 6F, 0B, 44, 00, C7, 05, 4C, 54, 46, 00, 5F, 02, 44, 00, C7, 05, 50, 54, 46, 00, C1, 01, 44, 00, C7, 05, 54, 54, 46, 00, 4D, 01, 44, 00, C3, 8B, FF, 55, 8B, EC, E8, 96, FF, FF, FF, 83, 7D, 08, 00, 74, 05, E8, 51, 8F, 00, 00, DB...
 
[+]

Code size:
314 KB (321,536 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to NY1WV3659  (204.145.82.27:80)

TCP (HTTP):
Connects to ip-172-16-22-200.ec2.internal  (172.16.22.200:8080)

TCP (HTTP):
Connects to NY1WV3438  (204.145.82.24:80)

TCP (HTTP):
Connects to c4.3e.559e.ip4.static.sl-reverse.com  (158.85.62.196:80)

TCP (HTTP):
Connects to ny1wv3280.xglobe.net  (204.145.82.20:80)

TCP (HTTP):
Connects to w04.ttms.eu  (46.105.156.76:80)

TCP (HTTP):
Connects to ec2-52-72-47-106.compute-1.amazonaws.com  (52.72.47.106:80)

TCP (HTTP):
Connects to ec2-52-202-52-20.compute-1.amazonaws.com  (52.202.52.20:80)

TCP (HTTP):
Connects to w01.ttms.eu  (46.105.156.71:80)

TCP (HTTP SSL):
Connects to ec2-52-22-95-143.compute-1.amazonaws.com  (52.22.95.143:443)

TCP (HTTP):
Connects to aep9.com  (216.144.226.152:80)

TCP (HTTP):
Connects to NY1WV3561  (204.145.82.26:80)

TCP (HTTP SSL):
Connects to 113-125-232-198.static.unitasglobal.net  (198.232.125.113:443)

TCP (HTTP SSL):
Connects to ec2-52-6-91-196.compute-1.amazonaws.com  (52.6.91.196:443)

TCP (HTTP):
Connects to ec2-52-202-119-97.compute-1.amazonaws.com  (52.202.119.97:80)

TCP (HTTP):
Connects to s3-1.amazonaws.com  (54.231.40.58:80)

TCP (HTTP):
Connects to ec2-52-71-87-48.compute-1.amazonaws.com  (52.71.87.48:80)

TCP (HTTP):
Connects to ec2-52-54-202-81.compute-1.amazonaws.com  (52.54.202.81:80)

TCP (HTTP SSL):
Connects to 94.31.29.54.IPYX-077437-ZYO.above.net  (94.31.29.54:443)

Remove safeup.exe - Powered by Reason Core Security