WajamInternetEnhancer.exe

Wajam Internet Enhancer

Wajam Internet Technologies Inc.

The file is part of Wajam, a web browser extension that injects social search integration into various search portals such as Google. The application WajamInternetEnhancer.exe has been detected as adware by 2 anti-malware scanners. This executable runs as a local area network (LAN) Internet proxy server listening on port 56651 and has the ability to intercept and modify all inbound and outbound Internet traffic on the local host. While running, it connects to the Internet address user-12.pl107450.fiber.net on port 80 using the HTTP protocol.
Publisher:
Wajam Internet Technologies Inc.

Product:
Wajam Internet Enhancer

Version:
0.0.0.0

MD5:
02e53b4831110ec87397db2535ea1b59

SHA-1:
fe4dd0a960cfd3d8f85ddb0270a73ae558cffad4

SHA-256:
ea31dbfe391ea9ac5d51146b0e320bc18e94a87178a94e34701b44a499997a76

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
11/23/2024 9:25:38 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Wajam
4.0.3.14827

Reason Heuristics
PUP.WajamInternetTechnologies.V
14.8.27.22

File size:
75.5 KB (77,312 bytes)

Product version:
0.0.0.0

Copyright:
Copyright © 2014

Original file name:
WajamInternetEnhancer.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\wajam\wajam internet enhancer\wajaminternetenhancer.exe

File PE Metadata
Compilation timestamp:
5/14/2014 4:29:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:2Rv9p9UVaFfh8hXTfJYJ+N7FKm+Rqyqsi/Ow6ggJpt:2x9zUVaFpCTJ7FKmuqh16ga/

Entry address:
0x1404E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.7596

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
72.5 KB (74,240 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:56651/

Local host port:
56651

Default credentials:
No


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to user-12.pl107450.fiber.net  (209.90.80.12:80)

TCP (HTTP SSL):
Connects to gru06s09-in-f9.1e100.net  (173.194.118.9:443)

TCP (HTTP SSL):
Connects to gru06s09-in-f5.1e100.net  (173.194.118.5:443)

TCP (HTTP SSL):
Connects to gru06s09-in-f31.1e100.net  (173.194.118.31:443)

TCP (HTTP SSL):
Connects to gru06s09-in-f23.1e100.net  (173.194.118.23:443)

TCP (HTTP):
Connects to ec2-54-208-30-101.compute-1.amazonaws.com  (54.208.30.101:80)

TCP (HTTP SSL):
Connects to 94.31.29.192.IPYX-077437-ZYO.above.net  (94.31.29.192:443)

Remove WajamInternetEnhancer.exe - Powered by Reason Core Security