SurfCanyonDesktop.exe

Surf Canyon Desktop

Surf Canyon Incorporated

The application SurfCanyonDesktop.exe by Surf Canyon has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SurfCanyonDesktop’.
Publisher:
Surf Canyon  (signed by Surf Canyon Incorporated)

Product:
Surf Canyon Desktop

Version:
1.3.6.0

MD5:
67f197557e8dce01c0675c4a69d2cc47

SHA-1:
9a5dde55f5aa67069f37ecbde07feeb758cddd98

SHA-256:
2cdeec28a33d7b05470d65eff2f7134f9e188c2e0611be8664c27b29bedf77be

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 3:44:41 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Startup.SurfCanyonorporated.R
14.10.7.9

File size:
91.8 KB (94,032 bytes)

Product version:
1.3.6.0

Copyright:
Copyright © 2013

Original file name:
SurfCanyonDesktop.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\surf canyon\surfcanyondesktop.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/12/2013 7:00:00 PM

Valid to:
3/13/2017 7:59:59 PM

Subject:
CN=Surf Canyon Incorporated, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Surf Canyon Incorporated, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1F54086556A315E8D932AFD0318766A3

File PE Metadata
Compilation timestamp:
3/12/2014 3:50:24 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:nLoaQm0BJzzGK2D6KtfXh1zSSSMMdXloEt9:nLoaQmFK2DDtfh9w5loK

Entry address:
0x1547E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6625

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
77.5 KB (79,360 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SurfCanyonDesktop

Command:
C:\Program Files\surf canyon\surfcanyondesktop.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to qu-in-f106.1e100.net  (209.85.201.106:80)

TCP (HTTP):
Connects to qu-in-f104.1e100.net  (209.85.201.104:80)

Remove SurfCanyonDesktop.exe - Powered by Reason Core Security