torntv.exe

TornTVApp

CHUTCHAI KIEWNOY

The application torntv.exe, “TornTV Application” by CHUTCHAI KIEWNOY has been detected as adware by 14 anti-malware scanners. This is a setup program which is used to install the application. The setup installer will bundle multiple adware offers during download and setup (based on the user's geographical location) including toolbars, extensions and coupon utilities. The file has been seen being downloaded from cmpsmarter-downloader.maynemyltf.netdna-cdn.com. While running, it connects to the Internet address 178-175-130-163.static.host on port 80 using the HTTP protocol.
Publisher:
TornTV.com  (signed by CHUTCHAI KIEWNOY)

Product:
TornTVApp

Description:
TornTV Application

Version:
2.0.0.1

MD5:
ef1ade4ec30e69c2a31789b69564bdfb

SHA-1:
d9a36cc34b1b7dc6c4c62d6f7590cf7e7ba78f1d

SHA-256:
df575c81fa29b2bfceed03b95c43c0ece1c07f6d3d2bc3c4fa0351757304084f

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Bundles a number of adware programs in the installer.

Analysis date:
11/23/2024 5:52:19 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Yontoo
7.1.1

AVG
Generic
2015.0.3256

Dr.Web
Adware.Yontoo.25
9.0.1.0353

IKARUS anti.virus
not-a-virus:AdWare.Yontoo
t3scan.1.8.5.0

Kaspersky
not-a-virus:AdWare.NSIS.Yontoo
14.0.0.2775

McAfee
Artemis!E876E34992E8
5600.6912

nProtect
Trojan-Clicker/W32.Agent.827648
14.12.11.01

Panda Antivirus
Generic Suspicious
14.12.19.01

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.CHUTCHAIKIEWNOY.G
14.10.8.13

Trend Micro House Call
Suspicious_GEN.F47V1210
7.2.353

Vba32 AntiVirus
AdWare.Yontoo
3.12.26.3

VIPRE Antivirus
CoolMirage Ltd
35640

Zillya! Antivirus
Adware.Yontoo.Win32.51
2.0.0.2003

File size:
808.2 KB (827,640 bytes)

Product version:
2.0.0.1

Copyright:
(c) TornTV.com All rights reserved.

Original file name:
TornTVApp.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\torntv.com\torntv.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/30/2014 2:00:00 AM

Valid to:
10/1/2015 1:59:59 AM

Subject:
CN=CHUTCHAI KIEWNOY, OU=Individual Developer, O=No Organization Affiliation, L=Phuket, S=Phuket, C=TH

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
70CF135290F3FC7E7BD27C7B350CF722

File PE Metadata
Compilation timestamp:
4/7/2013 12:55:55 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:310Q37SEEY8i3J7iFf6cH5B+5fbK3qvSmE+mPP7j8Iru9XL/by3Co:3yYef66DaTK3q68aP74Iruly

Entry address:
0x20D21

Entry point:
E8, 63, 74, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 58, 59, 87, 04, 24, FF, E0, 58, 59, 87, 04, 24, FF, E0, 8B, FF, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, 9D, 0D, 42, 00, 6A, 00, FF, 75, 0C, FF, 75, F8, FF, 75, 08, E8, 53, 05, 01, 00, 8B, 45, 0C, 8B...
 
[+]

Code size:
201.5 KB (206,336 bytes)

The file torntv.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to sage.parklogic.com  (69.39.236.56:80)

TCP (HTTP):

TCP (HTTP):
Connects to 178-175-130-163.static.host  (178.175.130.163:80)

TCP (HTTP):
Connects to unknown.prolexic.com  (72.52.4.90:80)

TCP (HTTP):
Connects to vps5780.inmotionhosting.com  (173.247.245.75:80)

TCP (HTTP):
Connects to vip1.g5.cachefly.net  (205.234.175.175:80)

TCP (HTTP):
Connects to ec2-54-84-217-106.compute-1.amazonaws.com  (54.84.217.106:80)

TCP (HTTP):
Connects to ns3013993.ip-149-202-76.eu  (149.202.76.60:80)

TCP (HTTP SSL):
Connects to ec2-52-55-195-249.compute-1.amazonaws.com  (52.55.195.249:443)

TCP (HTTP SSL):
Connects to ec2-52-201-97-156.compute-1.amazonaws.com  (52.201.97.156:443)

TCP (HTTP):
Connects to 8-29-154-46.bhsrv.net  (8.29.154.46:80)

Remove torntv.exe - Powered by Reason Core Security