Boost My PC.exe

Speedbit Technology

The executable Boost My PC.exe has been detected as malware by 1 anti-virus scanner. It runs as a scheduled task under the Windows Task Scheduler.
Publisher:
Boost My PC  (signed by Speedbit Technology)

Product:
Boost My PC

Version:
1.0.3.0

MD5:
325110cdd46207925e355b7b58621fd8

SHA-1:
0e73a660cd04ec7574b3b69357aa13d1d54fea49

SHA-256:
b1f338cf93afe07ff93c9eef49d411e759bf5f5c3881fbaffe6ba9edc570b509

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
5/2/2024 5:02:29 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Optional.BoostMyPC (L)
16.10.26.14

File size:
34.6 MB (36,262,544 bytes)

Product version:
1.0.3.0

Copyright:
Boost My PC. All rights reserved.

Original file name:
Boost My PC.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\boost my pc\boost my pc.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/14/2015 8:00:00 PM

Valid to:
5/14/2020 7:59:59 PM

Subject:
CN=Speedbit Technology, O=Speedbit Technology, STREET="H No-1626, Sector-15, Part-II", L=Gurgaon, S=Haryana, PostalCode=122001, C=IN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F6BF5DD416C9DC206FE375E5B09C6FCC

File PE Metadata
Compilation timestamp:
10/25/2016 7:58:09 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
393216:M+Q55izcA8x8YBwarXGniOMEIOQHUcYK4Pl8YT:U55izcA8x8YBwarXGnOEIOtK4Pl8YT

Entry address:
0x4D9BD

Entry point:
E8, ED, 94, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 50, DB, 57, 00, 75, 02, F3, C3, E9, 6F, 95, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 80, 48, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, D2, 0F, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 50, 13, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, BF, 12, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73...
 
[+]

Entropy:
4.7344

Code size:
1.1 MB (1,145,344 bytes)

Scheduled Task
Task name:
Boost My PC Scan

Trigger:
Weekly (Runs weekly on Wednesdays at 12:00 PM)

Description:
Runs Boost My PC at Scheduled Time.


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to esellerate-store5.digitalriver.com  (207.250.191.19:80)

TCP (HTTP SSL):
Connects to store5.esellerate.net  (207.250.191.17:443)

TCP (HTTP SSL):
Connects to server-54-192-55-156.jfk6.r.cloudfront.net  (54.192.55.156:443)

TCP (HTTP):
Connects to esellerate-store3.digitalriver.com  (8.18.233.57:80)

TCP (HTTP SSL):
Connects to ec2-184-72-32-226.us-west-1.compute.amazonaws.com  (184.72.32.226:443)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP SSL):
Connects to a104-119-124-148.deploy.static.akamaitechnologies.com  (104.119.124.148:443)

Remove Boost My PC.exe - Powered by Reason Core Security