stormwatchsetup.exe

StormWatch

Weather Protector LLC

Part of an adware web browser extension that delivers advertisements such as coupons, price-comparisons, display media, affiliate links, banners, popups/popunders and other links. The application stormwatchsetup.exe by Weather Protector has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from i.vertitechnologygroup.com.
Publisher:
Weather Protector LLC  (signed and verified)

Product:
StormWatch

Version:
1.0.2.43

MD5:
9ec9a4e34f2842bcbcb826a4d6d22531

SHA-1:
1019e026b000680433814ea604789a429e4214ef

SHA-256:
ec8562d03fc713c8c9daa1fba277eb8ad6ff014483a1b405db305c3fb00a354f

Scanner detections:
11 / 68

Status:
Adware

Analysis date:
12/24/2024 1:42:25 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
ADWARE/Adware.Gen7
3.6.1.96

Dr.Web
Adware.Plugin.962
9.0.1.090

ESET NOD32
Win32/Verti.L potentially unwanted
9.11407

Fortinet FortiGate
Riskware/Verti
3/31/2015

K7 AntiVirus
Unwanted-Program
13.202.15443

Malwarebytes
PUP.Optional.StormWatch.A
v2015.03.31.10

McAfee
Artemis!5D882E29019E
5600.6809

Reason Heuristics
PUP.Installer.Weather
15.3.31.22

Sophos
Generic PUA CL
4.98

Trend Micro House Call
Suspicious_GEN.F47V0331
7.2.90

File size:
549.6 KB (562,744 bytes)

Product version:
1.0.2.43

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\stormwatchsetup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/12/2014 8:00:00 PM

Valid to:
6/13/2015 7:59:59 PM

Subject:
CN=Weather Protector LLC, O=Weather Protector LLC, STREET="101 Colorado St #2309", L=Austin, S=TX, PostalCode=78701, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00833BECDB30CAD96C0E0AC4DF14A0329F

File PE Metadata
Compilation timestamp:
12/5/2009 5:52:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:3SYFSYmWaUXa6g9Jd4G17ohJLqzYD4bYA4SHn+4XXD2EycnGingRDS7LBJsT1D3R:JvaCaXJBMhFqzA4nH+GDGyYDVjR

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 6F, 44, 00, E8, 09, 2C, 00, 00, A3, A4, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 2E, 44, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.8389

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file stormwatchsetup.exe has been seen being distributed by the following URL.

Remove stormwatchsetup.exe - Powered by Reason Core Security