SearchDonkeyService.exe

SearchDonkey Service

WebAppTech Coding LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The application SearchDonkeyService.exe by WebAppTech Coding has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “SearchDonkey”.
Publisher:
WebAppTech Coding, LLC  (signed by WebAppTech Coding LLC)

Product:
SearchDonkey Service

Version:
1.0.0.0

MD5:
ccef4ba3e2381132a538fb3759f8fdd7

SHA-1:
0aff7543b31e28703db8e5c9e5395e2ab6a48f57

SHA-256:
ebc5d1e80ea8dc6d464a7bdb8b088b2c045806425f85b6ab1f13c44aad0f79c9

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
11/23/2024 2:37:57 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt (M)
16.12.3.13

File size:
53.4 KB (54,648 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © WebAppTech Coding, LLC 2014

Original file name:
SearchDonkeyService.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\searchdonkey\searchdonkeyservice.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/23/2013 7:00:00 PM

Valid to:
12/24/2014 6:59:59 PM

Subject:
CN=WebAppTech Coding LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WebAppTech Coding LLC, L=Grandville, S=Michigan, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1A6411A4888DF6223DF9C572F9BE2E96

File PE Metadata
Compilation timestamp:
2/13/2014 2:05:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:oZzGxHiByArQogDLcv6N4q1/0EBV4XJL6gGzZyt8:olGxHiByArQ3X46/J4XJL6gGcW

Entry address:
0xCE9E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.8914

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
44 KB (45,056 bytes)

Service
Display name:
SearchDonkey

Description:
Provides system level support for SearchDonkey.

Type:
Win32OwnProcess


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-52-10-180-179.us-west-2.compute.amazonaws.com  (52.10.180.179:80)

Remove SearchDonkeyService.exe - Powered by Reason Core Security