bittorrent-toolbar-torrentseek.exe

Conduit Ltd.

The file belongs to the Conduit API platform, a utility that bundles and monetizes search toolbars and web browser extensions. The application bittorrent-toolbar-torrentseek.exe, “TorrentSeek Toolbar” by Conduit has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the Wise Installer installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from files.downloadnow.com. While running, it connects to the Internet address cms.distributionengine.conduit-services.com on port 80 using the HTTP protocol.
Publisher:
Conduit Ltd.  (signed and verified)

Description:
TorrentSeek Toolbar

Version:
4.5.123.0

MD5:
7aceb08c3c062e1980f7dc3d180e9f25

SHA-1:
c06e3c5c195e9bf1b26470d9abd275388af7f5ca

SHA-256:
b240be0ad6797c06973cc8e149bc4a7b0fc687ea45c5d4d20d0681bde9c6819a

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
This component is distributed and installed with the Conduit Toolbar platform.

Analysis date:
4/24/2024 8:35:19 PM UTC  (today)

Scan engine
Detection
Engine version

F-Prot
File is damaged
v6.4.6.5.141

Reason Heuristics
PUP.TorrentSeekToolbar.Conduit.EE
14.8.7.22

Sophos
Mal/Generic-L
4.72

File size:
745 KB (762,896 bytes)

Copyright:
Platforma Online Ltd.

File type:
Executable application (Win32 EXE)

Installer:
Wise Installer

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\bittorrent-toolbar-torrentseek.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/22/2006 5:00:00 PM

Valid to:
3/23/2007 4:59:59 PM

Subject:
CN=Conduit Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Conduit Ltd., S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
158933A2A2DC96D4CA6543F694D06332

File PE Metadata
Compilation timestamp:
4/8/1999 1:24:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:QlmhLR65MMFtCTlohVbTbvwMSPD2RP9QNHJhaSQgBI33vbe3Jv0NO02+xkTfk2jt:QkUMMFNV30H2RP96mPvbav0jmTfk2jUi

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, 78, 05, 00, 00, 53, 56, BE, 04, 01, 00, 00, 57, 8D, 85, 94, FD, FF, FF, 56, 33, DB, 50, 53, FF, 15, 34, 20, 40, 00, 8D, 85, 94, FD, FF, FF, 56, 50, 8D, 85, 94, FD, FF, FF, 50, FF, 15, 30, 20, 40, 00, 8B, 3D, 2C, 20, 40, 00, 53, 53, 6A, 03, 53, 6A, 01, 8D, 85, 94, FD, FF, FF, 68, 00, 00, 00, 80, 50, FF, D7, 83, F8, FF, 89, 45, FC, 0F, 84, 7B, 01, 00, 00, 8D, 85, 90, FC, FF, FF, 50, 56, FF, 15, 28, 20, 40, 00, 8D, 85, 98, FE, FF, FF, 50, 53, 8D, 85, 90, FC, FF, FF, 68, 10, 30, 40, 00, 50...
 
[+]

Entropy:
7.9869

Packer / compiler:
Wise Installer Stub

Code size:
512 Bytes (512 bytes)

The file bittorrent-toolbar-torrentseek.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):

 
http://offering.service.distributionengine.conduit-services.com/DecisionEngine.ashx

TCP (HTTP):
Connects to cms.distributionengine.conduit-services.com  (54.243.251.51:80)

Remove bittorrent-toolbar-torrentseek.exe - Powered by Reason Core Security