webprotectorplus.exe

The application webprotectorplus.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Web Protector Plus Agent’. While running, it connects to the Internet address 2.6d.3a25.ip4.static.sl-reverse.com on port 80 using the HTTP protocol.
MD5:
049da1d88c864ca08c4e89dbb97d4dee

SHA-1:
0e6c75db284c6964f224827195b4eea141173ff3

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 8:28:05 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebProtectorPlus
17.3.7.22

File size:
399.5 KB (409,088 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\webprotectorplus\webprotectorplus.exe

File PE Metadata
Compilation timestamp:
2/19/2015 5:27:21 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xCCF8

Entry point:
F2, F7, C2, 36, BB, CE, F8, B2, 6B, 8D, 15, 99, F0, 54, 99, 31, D1, 0F, B6, EC, 15, 4C, D4, 1F, BE, 0F, B7, D8, 8B, F7, 2B, F8, 4B, 87, EB, 87, FD, 72, 02, B5, 15, B8, C0, AC, B4, 14, 88, DE, 68, BC, 04, 6C, 00, 68, A4, 03, 8F, 00, 8D, 1D, 98, B4, B4, 3C, 0F, BE, EC, E8, 94, 00, 00, 00, 88, E7, 04, 55, 69, FA, BE, B1, 68, B4, FE, C1, B4, 86, 3B, EB, FE, C5, F6, C3, 27, 0F, B7, FD, F3, 8D, 1D, AE, 54, F5, 6B, 68, AA, 0B, 00, 00, F7, C2, 1D, 82, C0, 88, 49, 58, 8D, 0D, 73, 0E, 9B, 9F, 8D, 35, 0B, 26, 15, 37...
 
[+]

Entropy:
5.9186

Code size:
120 KB (122,880 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Web Protector Plus Agent

Command:
"C:\Program Files\webprotectorplus\webprotectorplus.exe"


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 2.6d.3a25.ip4.static.sl-reverse.com  (37.58.109.2:80)

Remove webprotectorplus.exe - Powered by Reason Core Security