uvconverter.exe

The application uvconverter.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. It runs as a windows Service named “Convxxxx”. While running, it connects to the Internet address server-54-239-132-205.sfo9.r.cloudfront.net on port 80 using the HTTP protocol.
MD5:
026fb1467c7c9d78fa6dba7df80aa3d0

SHA-1:
63e826e91841c3c816f4631cb43e889cd199b94e

SHA-256:
4190369e37e174049aeda0bfc5148a7a51a1495cd784de2cb4bcad8c4cb336c8

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 11:37:16 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AegisLab AV Signature
Adwareare.Elex.Kmech!c
2.1.4+

Avira AntiVirus
ADWARE/ELEX.kmech
8.3.3.4

AVG
Generic7
2017.0.2525

Bkav FE
W32.eHeur.Malware10
1.3.0.8455

ESET NOD32
Win32/Adware.ELEX.BY application
6.3.12010.0

K7 AntiVirus
Adware
13.246.21816

McAfee
RDN/Generic PUP.x
5600.6181

Rising Antivirus
Malware.Undefined!8.C-CwgbaQuX5AI (cloud)
23.00.65.161216

Sophos
Generic PUA GD (PUA)
4.98

Trend Micro House Call
TROJ_GEN.R01BH06LF16
7.2.353

VIPRE Antivirus
Trojan.Win32.Generic
54538

ViRobot
Trojan.Win32.Z.Agent.440832.DS[h]
2014.3.20.0

File size:
430.5 KB (440,832 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\hadha\uvconverter.exe

File PE Metadata
Compilation timestamp:
12/11/2016 7:33:26 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

Entry address:
0x2EE48

Entry point:
E8, 0F, 96, 00, 00, E9, 7B, FE, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 20, B3, 45, 00, 33, C5, 89, 45, FC, 83, 7D, 08, FF, 57, 74, 09, FF, 75, 08, E8, 95, 5F, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 6A, 4C, 8D, 85, E4, FC, FF, FF, 6A, 00, 50, E8, 24, 70, 00, 00, 8D, 85, E0, FC, FF, FF, 89, 85, D8, FC, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, DC, FC, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC...
 
[+]

Entropy:
6.0993

Code size:
301.5 KB (308,736 bytes)

Service
Display name:
Convxxxx

Type:
Win32OwnProcess, InteractiveProcess


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-216-153.mrs50.r.cloudfront.net  (54.230.216.153:80)

TCP (HTTP):
Connects to server-54-240-186-249.mad50.r.cloudfront.net  (54.240.186.249:80)

TCP (HTTP):
Connects to server-54-230-216-234.mrs50.r.cloudfront.net  (54.230.216.234:80)

TCP (HTTP):
Connects to server-54-240-186-222.mad50.r.cloudfront.net  (54.240.186.222:80)

TCP (HTTP):
Connects to server-54-230-216-52.mrs50.r.cloudfront.net  (54.230.216.52:80)

TCP (HTTP):
Connects to server-54-230-216-17.mrs50.r.cloudfront.net  (54.230.216.17:80)

TCP (HTTP):
Connects to server-54-230-216-20.mrs50.r.cloudfront.net  (54.230.216.20:80)

TCP (HTTP):
Connects to server-54-230-206-217.atl50.r.cloudfront.net  (54.230.206.217:80)

TCP (HTTP):
Connects to server-54-192-14-245.ams1.r.cloudfront.net  (54.192.14.245:80)

TCP (HTTP):
Connects to server-52-85-74-61.lhr3.r.cloudfront.net  (52.85.74.61:80)

TCP (HTTP):
Connects to server-54-230-206-216.atl50.r.cloudfront.net  (54.230.206.216:80)

TCP (HTTP):
Connects to server-54-230-206-116.atl50.r.cloudfront.net  (54.230.206.116:80)

TCP (HTTP):
Connects to server-54-240-186-29.mad50.r.cloudfront.net  (54.240.186.29:80)

TCP (HTTP):
Connects to server-54-230-206-96.atl50.r.cloudfront.net  (54.230.206.96:80)

TCP (HTTP):
Connects to server-54-230-206-118.atl50.r.cloudfront.net  (54.230.206.118:80)

TCP (HTTP):
Connects to server-54-230-187-105.cdg51.r.cloudfront.net  (54.230.187.105:80)

TCP (HTTP):
Connects to server-52-85-221-114.cdg50.r.cloudfront.net  (52.85.221.114:80)

TCP (HTTP):
Connects to server-54-239-132-8.sfo9.r.cloudfront.net  (54.239.132.8:80)

TCP (HTTP):
Connects to server-54-230-206-22.atl50.r.cloudfront.net  (54.230.206.22:80)

TCP (HTTP):
Connects to server-54-230-163-38.jax1.r.cloudfront.net  (54.230.163.38:80)

Remove uvconverter.exe - Powered by Reason Core Security