StormAlerts.exe

StormAlerts

Weather Warnings LLC

Part of an adware web browser extension that delivers advertisements such as coupons, price-comparisons, display media, affiliate links, banners, popups/popunders and other links. The application StormAlerts.exe by Weather Warnings has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. Additionally, the file is typically installed by a number of programs including StormAlerts by Weather Warnings LLC and Storm Alerts Pro Version by Weather Warnings LLC, both potentially unwanted software.
Publisher:
Weather Warnings LLC  (signed and verified)

Product:
StormAlerts

Version:
1.6.0.0

MD5:
7dcada47db261ccd331554e12dccfd89

SHA-1:
118ae9f65919141838665880c43654b53950c234

SHA-256:
f50c95aa5cf060f2cf5c577d77e7b2f8a6c853d183b296c93e7aa7d60e0e0ad9

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 7:58:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WeatherWarnings.L
14.8.8.1

File size:
166.2 KB (170,160 bytes)

Product version:
1.6.0.0

Trademarks:
StormAlerts is a trademark of Weather Warnings LLC

Original file name:
StormAlerts.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\stormalerts\stormalerts.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/15/2013 5:00:00 PM

Valid to:
10/16/2014 4:59:59 PM

Subject:
CN=Weather Warnings LLC, O=Weather Warnings LLC, STREET="250 Park Ave #504", L=Minneapolis, S=MN, PostalCode=55415, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E8DB5153F5DF039D40C9CA815EC69821

File PE Metadata
Compilation timestamp:
12/30/2013 10:05:36 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:tYVzF2/S+6Ak9I4CQzIbRrOHIEa3omnFuhhCmztr1+PhQHZk:tY/MEqszI16HVOOh/51+G5k

Entry address:
0xB8FE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
3.7670

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
40 KB (40,960 bytes)

The file StormAlerts.exe has been discovered within the following programs.

Storm Alerts Pro Version  by Weather Warnings LLC
This is a potentially unwanted program (PUP) that bundles various additional offers during setup, typically ad-supported (adware) in functionality.
86% remove it
StormAlerts  by Weather Warnings LLC
StormAlerts is an ad-supported free web browser extension. The program will also randomly popup various advertisements in a window when the user uses their PC regardless if they are using the web browser or not.
www.storm-alerts.net
86% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to a172-224-7-197.deploy.static.akamaitechnologies.com  (172.224.7.197:80)

TCP (HTTP):
Connects to ocsp.comodoca.com  (178.255.83.1:80)

TCP (HTTP):
Connects to nesdis-woc2.boulder.noaa.gov  (140.172.17.21:80)

TCP (HTTP):
Connects to nesdis-ssmc.woc.noaa.gov  (140.90.33.11:80)

TCP (HTTP):
Connects to a23-220-103-40.deploy.static.akamaitechnologies.com  (23.220.103.40:80)

TCP (HTTP):
Connects to a23-207-143-54.deploy.static.akamaitechnologies.com  (23.207.143.54:80)

TCP (HTTP):

TCP (HTTP SSL):
Connects to a104-117-139-128.deploy.static.akamaitechnologies.com  (104.117.139.128:443)

TCP (HTTP):
Connects to 75.fe.a86c.ip4.static.sl-reverse.com  (108.168.254.117:80)

Remove StormAlerts.exe - Powered by Reason Core Security