StrongholdAntiMalware.exe

Stronghold AntiMalware

Security Stronghold LLC

The application StrongholdAntiMalware.exe by Security Stronghold has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Stronghold AntiMalware’. While running, it connects to the Internet address ns1.vistaglance.com on port 80 using the HTTP protocol.
Publisher:
Security Stronghold  (signed by Security Stronghold LLC)

Product:
Stronghold AntiMalware

Version:
1.3.0.0

MD5:
77cf15c712b132dffbc47e87204c1938

SHA-1:
4a42e13c7503ff557b8d17923ed252e9718f8e38

SHA-256:
84cc880dc8f4710dcf6705af81bce179eccd02d647d2f895dcc00d2faa9a0fa3

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 4:14:57 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
17.3.13.22

File size:
7.8 MB (8,152,448 bytes)

Product version:
1.3.0.0

Copyright:
Copyright 2003-2016 Security Stronghold

Original file name:
StrongholdAntiMalware.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\stronghold antimalware\strongholdantimalware.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/30/2017 9:35:42 AM

Valid to:
3/13/2018 11:49:56 AM

Subject:
E=manager@securitystronghold.com, CN=Security Stronghold LLC, O=Security Stronghold LLC, L=Astrakhan, S=Astrakhan Oblast, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G3, O=GlobalSign nv-sa, C=BE

Serial number:
5BA3B7B6EC10E094571B5F3F

File PE Metadata
Compilation timestamp:
3/10/2017 1:32:23 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x587F98

Entry point:
55, 8B, EC, B9, 08, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, F0, 43, 97, 00, E8, 78, 56, A8, FF, 8B, 35, B0, 55, 9D, 00, 33, C0, 55, 68, ED, 85, 98, 00, 64, FF, 30, 64, 89, 20, E8, 83, 9F, FD, FF, 8B, 06, E8, 6C, AA, BD, FF, 8B, 06, 33, D2, E8, 5B, A4, BD, FF, 8B, 06, BA, 08, 86, 98, 00, E8, 4F, A4, BD, FF, 8D, 45, EC, E8, 33, EF, BE, FF, 8D, 45, EC, BA, 44, 86, 98, 00, E8, 5A, 1E, A8, FF, 8B, 45, EC, E8, 96, 40, CF, FF, 84, C0, 0F, 84, 5F, 02, 00, 00, B8, 64, 86, 98, 00, E8, 54, 9C, C2, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
5.5 MB (5,796,864 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Stronghold AntiMalware

Command:
C:\Program Files\stronghold antimalware\strongholdantimalware.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to server.ssh2datastore.com  (64.37.59.154:443)

TCP (HTTP):
Connects to ns1.vistaglance.com  (66.7.217.40:80)

Remove StrongholdAntiMalware.exe - Powered by Reason Core Security