winrar_tsv4d3vhu.exe

ClientConnect LTD

The file belongs to the ClientConnect (Conduit/Perion) platform, a utility that bundles and monetizes search toolbars and browser add-ons. The application winrar_tsv4d3vhu.exe by ClientConnect has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the Perion Download Manager installer. The installer is marketed through download protals and search ads as WinRAR archiver but will also install additional software offers which include adware, PUPs and browser toolbars. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from de.mirroring-contentfiles-k.com and multiple other hosts. While running, it connects to the Internet address cms.dmccint.com on port 80 using the HTTP protocol.
Publisher:
ClientConnect LTD  (signed and verified)

MD5:
13053232d588638fd9e21fc225ec8ba4

SHA-1:
11e7bb5b8ed534776065fc8a5de39fb51881e94d

SHA-256:
411fce0aa2a4eeb5b134f62659b91b2f9292b6fa862284b522b4d35d5bcb6086

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/27/2024 7:02:24 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3320

Baidu Antivirus
PUA.Win32.ClientConnect
4.0.3.141015

ESET NOD32
Win32/ClientConnect (variant)
8.10533

IKARUS anti.virus
PUA.Toolbar.Conduit
t3scan.1.7.8.0

Malwarebytes
PUP.Optional.ClientConnect
v2014.10.15.02

McAfee
Artemis!13053232D588
5600.6976

Reason Heuristics
PUP.ClientConnect.Q
14.10.15.14

File size:
620 KB (634,864 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Perion Download Manager (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\winrar_tsv4d3vhu.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
9/15/2014 8:00:00 PM

Valid to:
9/17/2015 7:59:59 PM

Subject:
CN=ClientConnect LTD, OU=DM6, O=ClientConnect LTD, L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
12A6FD0B37B9C113F37D28954E635514

File PE Metadata
Compilation timestamp:
2/24/2012 2:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:JEPJuupqexPS/hYO0ghjhIERfu6KaQPd+zFBSygEOOvEEStI8:JowupvqLjhlRfAt1aBSo3EH

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file winrar_tsv4d3vhu.exe has been seen being distributed by the following 3 URLs.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to cms.dmccint.com  (23.67.242.80:80)

 
http://cms.dmccint.com/DynamicOffer/11950781/11971904/?mainofferId=11947347&CurrentStep=2&TotalSteps=4&DownloadBrowser=IE&CType=-1&UserMode=-1&DMVersion=1.3.1.19.11970770.01&Language=US-EN

Remove winrar_tsv4d3vhu.exe - Powered by Reason Core Security