3426cb0e-4ffc-4c2e-ba21-a97ecc47aea5-10.exe

SavePass 1.1

OB

The application 3426cb0e-4ffc-4c2e-ba21-a97ecc47aea5-10.exe has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. While running, it connects to the Internet address hwcdn.net on port 80 using the HTTP protocol.
Publisher:
OB

Product:
SavePass 1.1

Description:
SavePass 1.1 exe

Version:
1000.1000.1000.1000

MD5:
b8b107e1af297315ea317797a02e5d86

SHA-1:
8591cee0530f1c9c4b92d0f504bce56c6524476e

SHA-256:
a6bb239c9edb0c07f15d18a41dac68b52ef685bde4809b43d334e181faed0cdf

Scanner detections:
1 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
5/26/2024 8:28:03 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Crossrider (M)
15.10.30.14

File size:
1.5 MB (1,572,352 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
SavePass 1.1.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\savepass 1.1\3426cb0e-4ffc-4c2e-ba21-a97ecc47aea5-10.exe

File PE Metadata
Compilation timestamp:
10/30/2015 12:06:21 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:d92xuB1R5El2IE843i5ox1nCNxvDc13dSaVuGATZpSw6DmHdc2jpzWN1qV7x:LBFQUF8b7e34TZpSw6ec2jpzWN1y7x

Entry address:
0xD1D5D

Entry point:
E8, 53, 06, 01, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, B8, 09, 56, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 58, D1, 55, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, B8, 09, 56, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8...
 
[+]

Code size:
1 MB (1,062,912 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-50-17-240-68.compute-1.amazonaws.com  (50.17.240.68:80)

TCP (HTTP):
Connects to s3-website-us-east-1.amazonaws.com  (54.231.120.169:80)

TCP (HTTP):
Connects to hwcdn.net  (69.16.175.42:80)

Remove 3426cb0e-4ffc-4c2e-ba21-a97ecc47aea5-10.exe - Powered by Reason Core Security