ShopAtHomeHelper.exe

ShopAtHome.com Browser App

ShopAtHome.com (Belcaro Group, Inc.)

The application ShopAtHomeHelper.exe, “ShopAtHome.com Cash Back Helper” by ShopAtHome.com (Belcaro Group,) has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program ShopAtHome.com Helper by Belcaro Group Inc. which is a potentially unwanted software program. The file has been seen being downloaded from toolbar.shopathome.com. While running, it connects to the Internet address 107.154.110.91.ip.incapdns.net on port 80 using the HTTP protocol.
Publisher:
ShopAtHome.com  (signed by ShopAtHome.com (Belcaro Group, Inc.))

Product:
ShopAtHome.com Browser App

Description:
ShopAtHome.com Cash Back Helper

Version:
7.10.8.4

MD5:
49b2e542a7ed7c44a2c4f84b5008df72

SHA-1:
1d321b55f3401ef9b9260d188db7a9a12dcca777

SHA-256:
7ead8cc6225dc4b9daa1f4eb2a05f10943c120df5f072f72c5591832aeadf33a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/15/2024 8:41:27 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ShopAtHome (M)
16.6.14.18

File size:
1.1 MB (1,125,184 bytes)

Product version:
7.10.8.4

Copyright:
(c) ShopAtHome.com. All rights reserved.

Original file name:
ShopAtHomeHelper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\shopathome\shopathomehelper\shopathomehelper.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
6/4/2014 7:00:00 PM

Valid to:
6/28/2017 6:59:59 PM

Subject:
CN="ShopAtHome.com (Belcaro Group, Inc.)", OU=IT, O="ShopAtHome.com (Belcaro Group, Inc.)", L=Greenwood Village, S=Colorado, C=US, SERIALNUMBER=19871692567, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Colorado, OID.1.3.6.1.4.1.311.60.2.1.3=US

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
38E3C208FF559249F35DC2BBDA16136B

File PE Metadata
Compilation timestamp:
6/8/2016 4:15:41 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:4wTG4VceFzzdpedqHCHipfsKOJZHvFr8sq8UCpROq3:hTfVceFzz3edqiCpBOJZHGspRpROq3

Entry address:
0x78439

Entry point:
E8, F1, A3, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 2C, A1, 44, C6, 4E, 00, 33, C5, 89, 45, FC, 56, FF, 75, 0C, 8B, 75, 08, 8D, 4D, D4, E8, AC, C2, FF, FF, 85, F6, 75, 24, E8, DC, D4, FF, FF, C7, 00, 16, 00, 00, 00, E8, C7, 2F, 00, 00, 80, 7D, E0, 00, 74, 07, 8B, 45, DC, 83, 60, 70, FD, D9, EE, EB, 35, 83, C6, 02, 0F, B7, 06, 6A, 08, 50, E8, B7, 73, 00, 00, 59, 59, 85, C0, 75, EC, 8D, 45, D4, 50, 8D, 45, E4, 56, 50, E8, 1F, A4, 00, 00, DD, 40, 10, 83, C4, 0C, 80, 7D, E0, 00, 74, 07, 8B, 45...
 
[+]

Entropy:
6.4593

Code size:
715.5 KB (732,672 bytes)

The file ShopAtHomeHelper.exe has been discovered within the following programs.

ShopAtHome.com Helper  by Belcaro Group Inc.
This is the helper application that is installed with the ShopAtHome Toolbar (Browser App).
www.shopathome.com
68% remove it
 
Powered by Should I Remove It?

The file ShopAtHomeHelper.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to 199.83.128.126.ip.incapdns.net  (199.83.128.126:80)

TCP (HTTP):
Connects to 199.83.135.126.ip.incapdns.net  (199.83.135.126:80)

TCP (HTTP):
Connects to 199.83.129.126.ip.incapdns.net  (199.83.129.126:80)

TCP (HTTP):
Connects to 199.83.134.126.ip.incapdns.net  (199.83.134.126:80)

TCP (HTTP):
Connects to 107.154.107.91.ip.incapdns.net  (107.154.107.91:80)

TCP (HTTP):
Connects to 107.154.105.91.ip.incapdns.net  (107.154.105.91:80)

TCP (HTTP):
Connects to 107.154.102.91.ip.incapdns.net  (107.154.102.91:80)

TCP (HTTP):
Connects to 149.126.73.126.ip.incapdns.net  (149.126.73.126:80)

TCP (HTTP):
Connects to 107.154.104.91.ip.incapdns.net  (107.154.104.91:80)

TCP (HTTP):
Connects to 107.154.110.91.ip.incapdns.net  (107.154.110.91:80)

TCP (HTTP):
Connects to 199.83.132.126.ip.incapdns.net  (199.83.132.126:80)

TCP (HTTP):
Connects to a184-51-114-64.deploy.static.akamaitechnologies.com  (184.51.114.64:80)

TCP (HTTP):
Connects to 107.154.121.91.ip.incapdns.net  (107.154.121.91:80)

TCP (HTTP):
Connects to 107.154.111.91.ip.incapdns.net  (107.154.111.91:80)

TCP (HTTP):
Connects to 107.154.109.91.ip.incapdns.net  (107.154.109.91:80)

TCP (HTTP):
Connects to 107.154.108.91.ip.incapdns.net  (107.154.108.91:80)

Remove ShopAtHomeHelper.exe - Powered by Reason Core Security