wikithemes.exe

Internet Widgits Pty Ltd

The application wikithemes.exe by Internet Widgits Pty has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WikiThemes’. While running, it connects to the Internet address server-54-230-158-169.sin3.r.cloudfront.net on port 443.
Publisher:
Internet Widgits Pty Ltd  (signed and verified)

MD5:
7c5c0d9ae44615324d25c24a73f159c5

SHA-1:
9970f1c4b5bd6b34872a4d6a33ff611cc58a682a

SHA-256:
bcc68ce9ef318c09b75a4d6aceb63d546fd0fda8622dc9d936913c251ec1c538

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 1:51:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.10.14

File size:
45.6 MB (47,852,648 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\wikithemes\wikithemes.exe

Digital Signature
Authority:
Internet Widgits Pty Ltd

Valid from:
11/14/2016 6:36:30 PM

Valid to:
11/12/2026 6:36:30 PM

Subject:
CN=WikiThemes, O=Internet Widgits Pty Ltd, S=Some-State, C=US

Issuer:
CN=WikiThemes, O=Internet Widgits Pty Ltd, S=Some-State, C=US

Serial number:
00BFAB17CFDB648FE9

File PE Metadata
Compilation timestamp:
2/17/2017 6:17:08 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x1C9A083

Entry point:
E8, 98, 3A, 01, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 8B, 55, 0C, A1, 20, A8, EC, 02, F7, D2, 8B, 4D, 08, 23, D0, 23, 4D, 0C, 0B, D1, 89, 15, 20, A8, EC, 02, 5D, C3, E8, A7, 20, 00, 00, 85, C0, 74, 08, 6A, 16, E8, 6A, 21, 00, 00, 59, F6, 05, 20, A8, EC, 02, 02, 74, 21, 6A, 17, E8, 97, 24, 60, 00, 85, C0, 74, 05, 6A, 07, 59, CD, 29, 6A, 01, 68, 15, 00, 00, 40, 6A, 03, E8, A7, F8, FF, FF, 83, C4, 0C, 6A, 03, E8, 14, FC, FF, FF, CC, 55, 8B, EC, 8D, 45, 18, 50, 6A, 00, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75...
 
[+]

Entropy:
6.8788

Code size:
34.9 MB (36,637,696 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WikiThemes

Command:
C:\users\{user}\appdata\roaming\wikithemes\wikithemes.exe su


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-23-23-117-76.compute-1.amazonaws.com  (23.23.117.76:80)

TCP (HTTP SSL):
Connects to text-lb.ulsfo.wikimedia.org  (198.35.26.96:443)

TCP (HTTP SSL):
Connects to server-54-230-158-169.sin3.r.cloudfront.net  (54.230.158.169:443)

TCP (HTTP SSL):
Connects to upload-lb.ulsfo.wikimedia.org  (198.35.26.112:443)

TCP (HTTP):
Connects to 5c.75.c0ad.ip4.static.sl-reverse.com  (173.192.117.92:80)

TCP (HTTP):
Connects to 89.9d.a86c.ip4.static.sl-reverse.com  (108.168.157.137:80)

TCP (HTTP):
Connects to 57.9d.a86c.ip4.static.sl-reverse.com  (108.168.157.87:80)

TCP (HTTP):
Connects to unknown.prolexic.com  (72.52.12.83:80)

TCP (HTTP SSL):
Connects to server-54-192-148-243.sin2.r.cloudfront.net  (54.192.148.243:443)

TCP (HTTP SSL):
Connects to wb-in-f156.1e100.net  (66.102.1.156:443)

TCP (HTTP SSL):
Connects to upload-lb.esams.wikimedia.org  (91.198.174.208:443)

TCP (HTTP SSL):
Connects to text-lb.esams.wikimedia.org  (91.198.174.192:443)

TCP (HTTP SSL):
Connects to server-54-192-138-5.lax1.r.cloudfront.net  (54.192.138.5:443)

TCP (HTTP SSL):
Connects to rtr3.l7.search.vip.ir2.yahoo.com  (217.12.15.96:443)

TCP (HTTP):
Connects to ec2-23-23-165-47.compute-1.amazonaws.com  (23.23.165.47:80)

TCP (HTTP):
Connects to ec2-107-21-245-181.compute-1.amazonaws.com  (107.21.245.181:80)

TCP (HTTP SSL):
Connects to e2.ycpi.vip.deb.yahoo.com  (87.248.118.23:443)

TCP (HTTP SSL):
Connects to server-54-192-202-97.fra50.r.cloudfront.net  (54.192.202.97:443)

TCP (HTTP SSL):
Connects to server-52-85-178-194.fra50.r.cloudfront.net  (52.85.178.194:443)

TCP (HTTP SSL):
Connects to mpr1.ngd.vip.ir2.yahoo.com  (217.12.15.83:443)

Remove wikithemes.exe - Powered by Reason Core Security