service.exe

Navigation network co.,limited

The application service.exe, “Windows Servis İşlemleri” by Navigation network co.,limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘service’. The file has been seen being downloaded from www.guzel.net. While running, it connects to the Internet address ip.sistem724.com.tr on port 80 using the HTTP protocol.
Publisher:
Navigation network co.,limited  (signed and verified)

Description:
Windows Servis İşlemleri

Version:
1.0.0.0

MD5:
7c4ca795cb9e07019e420f19c621ac4b

SHA-1:
e89e18bf7e5a1d0cb98b2a4360a6bea3e409561c

SHA-256:
58764f4f2c6d0263761bda4cb10af40a9ddd7cf59d5b39620dd7372b6c8fe28c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 3:09:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Startup.Navigationnetworkcolimited
15.3.7.3

File size:
605.1 KB (619,632 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

Common path:
C:\users\{user}\appdata\roaming\service.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/19/2014 2:00:00 AM

Valid to:
2/20/2016 1:59:59 AM

Subject:
CN="Navigation network co.,limited", OU=Software Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Navigation network co.,limited", L=Hongkong, S=Hongkong, C=HK

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2617E71F3DD61639E291AD2D048E1D8A

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:JyqHFmJA8q++O3zbgdXfdmY+bJZkpzMTsq:Jyqldi3zbcl78JZkpQTs

Entry address:
0x7EDB0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 28, EA, 47, 00, E8, AC, 78, F8, FF, A1, EC, 0B, 48, 00, 8B, 00, E8, 78, A8, FD, FF, 8B, 0D, 94, 0D, 48, 00, A1, EC, 0B, 48, 00, 8B, 00, 8B, 15, 30, B6, 47, 00, E8, 78, A8, FD, FF, A1, EC, 0B, 48, 00, 8B, 00, E8, EC, A8, FD, FF, E8, F7, 53, F8, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 32, 13, 8B, C0, 02, 00, 8B, C0, 00, 8D, 40, 00, 00, 8D, 40, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
503.5 KB (515,584 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
service

Command:
C:\users\{user}\appdata\roaming\service.exe


The file service.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ip.sistem724.com.tr  (91.191.172.102:80)

Remove service.exe - Powered by Reason Core Security