SunsetScreen.exe

SunsetScreen

Daniel White

The application SunsetScreen.exe by Daniel White has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program SunsetScreen by Skytopia. While running, it connects to the Internet address crl.comodoca.com.cdn.cloudflare.net on port 80 using the HTTP protocol.
Publisher:
Daniel White  (signed and verified)

Product:
SunsetScreen

Version:
1.24.0.0

MD5:
311f71ff82afb10e789fc2130cb88933

SHA-1:
9408da1f1def4d2a336d121e0ab0b7c8dd35a5fd

SHA-256:
99b751c75d164f603a103bd42a9a520307087af24782d9d8b1381ce1aca1fed0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 5:51:41 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Skytopia.Optional (L)
16.8.28.4

File size:
762.9 KB (781,232 bytes)

Product version:
1.24.0.0

Copyright:
Copyright © Daniel White 2015

Original file name:
SunsetScreen.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\sunsetscreen\sunsetscreen.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/18/2016 8:00:00 AM

Valid to:
7/19/2021 7:59:59 AM

Subject:
CN=Daniel White, O=Daniel White, STREET=25 Newmarket Road, L=Cannock, S=Staffs, PostalCode=WS119FF, C=GB

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C840265AB185D81247E87B6D754706E2

File PE Metadata
Compilation timestamp:
8/28/2016 9:38:08 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:bw7XyIkqa+bfEleDA3J7R2V13H/mo7C7fYluannZp9GasLV+kV2QecD9ZFSOSuWi:UX559ZsLok3ec93SOZWqVBtRlN3d

Entry address:
0xA8D4E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.7417

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
667.5 KB (683,520 bytes)

The file SunsetScreen.exe has been discovered within the following program.

SunsetScreen  by Skytopia
www.skytopia.com/software/sunsetscreen
About 6% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to crl.comodoca.com.cdn.cloudflare.net  (178.255.83.2:80)

Remove SunsetScreen.exe - Powered by Reason Core Security