abs_toolbar.exe

Conduit Ltd.

The file belongs to the Conduit API platform, a utility that bundles and monetizes search toolbars and web browser extensions. The application abs_toolbar.exe, “Absolutist Games Toolbar” by Conduit has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Wise Installer installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from fs.absolutist.com. While running, it connects to the Internet address cms.distributionengine.conduit-services.com on port 80 using the HTTP protocol.
Publisher:
Conduit Ltd.  (signed and verified)

Description:
Absolutist Games Toolbar

Version:
4.5.156.0

MD5:
0c8a9989d63509a7c23999201f97574d

SHA-1:
115ef55aff284f12f1dc5387944d2d8ab9b231ca

SHA-256:
965334c53aa1adf74ddb34fc6d0d3f4292b80476a69e153929a1f52875d2e46f

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
This component is distributed and installed with the Conduit Toolbar platform.

Analysis date:
4/19/2024 12:29:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.AbsolutistGamesToolbar.Conduit.L
14.8.7.22

File size:
831.3 KB (851,216 bytes)

Copyright:
Conduit Ltd.

File type:
Executable application (Win32 EXE)

Installer:
Wise Installer

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\abs_toolbar.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/17/2007 1:00:00 AM

Valid to:
3/24/2010 12:59:59 AM

Subject:
CN=Conduit Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Conduit Ltd., S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
59AB9B2EE67914B7DF4C479540DEC561

File PE Metadata
Compilation timestamp:
4/8/1999 10:24:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:AkAMbFOMy9pGDAz06+kVQELeTUrspOKD7t+/cUbR:AkdwMy2Q06XJe4IVDUk

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, 78, 05, 00, 00, 53, 56, BE, 04, 01, 00, 00, 57, 8D, 85, 94, FD, FF, FF, 56, 33, DB, 50, 53, FF, 15, 34, 20, 40, 00, 8D, 85, 94, FD, FF, FF, 56, 50, 8D, 85, 94, FD, FF, FF, 50, FF, 15, 30, 20, 40, 00, 8B, 3D, 2C, 20, 40, 00, 53, 53, 6A, 03, 53, 6A, 01, 8D, 85, 94, FD, FF, FF, 68, 00, 00, 00, 80, 50, FF, D7, 83, F8, FF, 89, 45, FC, 0F, 84, 7B, 01, 00, 00, 8D, 85, 90, FC, FF, FF, 50, 56, FF, 15, 28, 20, 40, 00, 8D, 85, 98, FE, FF, FF, 50, 53, 8D, 85, 90, FC, FF, FF, 68, 10, 30, 40, 00, 50...
 
[+]

Packer / compiler:
Wise Installer Stub

Code size:
512 Bytes (512 bytes)

The file abs_toolbar.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ude.conduit-data.com  (195.78.120.173:80)

TCP (HTTP):

 
http://offering.service.distributionengine.conduit-services.com/DecisionEngine.ashx

TCP (HTTP):
Connects to cms.distributionengine.conduit-services.com  (54.243.251.51:80)

Remove abs_toolbar.exe - Powered by Reason Core Security