ace_stream_media_3.1.15.exe

Innovative Digital Technologies

The application ace_stream_media_3.1.15.exe by Innovative Digital Technologies has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from dl.acestream.org and multiple other hosts. While running, it connects to the Internet address static.164.41.251.148.clients.your-server.de on port 80 using the HTTP protocol.
Publisher:
Innovative Digital Technologies  (signed and verified)

MD5:
06b95b774b0a1955e8c920ea3e6d8a8c

SHA-1:
39fae2cb3160d1eeb37ae79757eda82d0d7b6427

SHA-256:
4bcc40413d61ef81f23263eded414c5073249841a2f7b05484249fdea03fbd3d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 5:44:58 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InnovativeDigital (M)
17.2.2.11

File size:
79.5 MB (83,375,936 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ace_stream_media_3.1.15.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/14/2016 3:00:00 AM

Valid to:
6/15/2017 2:59:59 AM

Subject:
CN=Innovative Digital Technologies, O=Innovative Digital Technologies, STREET=38/40 A T.Shevchenko Blvd., L=Kyyiv, S=Kyyiv, PostalCode=01032, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7408D72DB44FD7A1F25C606006DCFF6E

File PE Metadata
Compilation timestamp:
7/25/2016 3:55:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x30D9

Entry point:
81, EC, 84, 01, 00, 00, 53, 56, 57, 33, DB, 68, 01, 80, 00, 00, 89, 5C, 24, 18, C7, 44, 24, 10, 98, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, A8, 70, 40, 00, FF, 15, A4, 70, 40, 00, 66, 3D, 06, 00, 74, 11, 53, E8, 7C, 2F, 00, 00, 3B, C3, 74, 07, 68, 00, 0C, 00, 00, FF, D0, BE, 98, 72, 40, 00, 56, E8, F8, 2E, 00, 00, 56, FF, 15, A0, 70, 40, 00, 8D, 74, 06, 01, 38, 1E, 75, EB, 55, 6A, 09, E8, 4F, 2F, 00, 00, 6A, 07, E8, 48, 2F, 00, 00, A3, 04, 37, 42, 00, FF, 15, 44, 70, 40, 00, 53, FF, 15, 88...
 
[+]

Code size:
23.5 KB (24,064 bytes)

The file ace_stream_media_3.1.15.exe has been seen being distributed by the following 3 URLs.

http://dl.acestream.org/Ace_Stream_Media_3.1.15.exe

http://dl.acestream.org/products/acestream-vlc-1.1.12/.../latest

http://dl.acestream.org/products/acestream-full/.../latest

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to static.165.41.251.148.clients.your-server.de  (148.251.41.165:80)

TCP (HTTP):
Connects to static.164.41.251.148.clients.your-server.de  (148.251.41.164:80)

TCP (HTTP):
Connects to static.163.41.251.148.clients.your-server.de  (148.251.41.163:80)

TCP (HTTP):
Connects to 203-144-144-166.static.asianet.co.th  (203.144.144.166:8080)

Remove ace_stream_media_3.1.15.exe - Powered by Reason Core Security