CCleaner.exe

1.3.8.7.131223.01

Perion Network Ltd.

The application CCleaner.exe by Perion Network has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from 638d79434b7746f9ba3bc20d32bebd4f.integration.download.conduit-services.com a web site host known to distribute potentially unwanted software operated by Conduit Ltd.. While running, it connects to the Internet address ude.databssint.com on port 80 using the HTTP protocol.
Publisher:
Perion Network Ltd.  (signed and verified)

Product:
1.3.8.7.131223.01

Description:
Setup.exe

Version:
1.3.8.7

MD5:
ca49522ef4b3d59231ebc507fd0a8cf7

SHA-1:
932e42fd896a414f45fc6947e5b3aa69e02ab14e

SHA-256:
fde91ed0957c93d9fc58168065ab805df366cf0632cfa64c834a3d00d7f8542a

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Analysis date:
5/10/2024 3:09:08 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Conduit
7.1.1

Dr.Web
Adware.Conduit.43
9.0.1.0103

ESET NOD32
Win32/Toolbar.Conduit.AB (variant)
8.9672

Malwarebytes
PUP.Optional.Conduit
v2014.04.13.09

Panda Antivirus
PUP/Conduit.A
14.04.13.09

Reason Heuristics
PUP.Installer.Perion.I
14.4.13.19

Trend Micro House Call
TROJ_GE.CBBDC1FF
7.2.103

VIPRE Antivirus
Conduit
28214

File size:
199.6 KB (204,440 bytes)

Product version:
1.3.8.7

Copyright:
Conduit Ltd.

Original file name:
CCleaner.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ccleaner.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/23/2012 8:00:00 PM

Valid to:
4/23/2015 7:59:59 PM

Subject:
CN=Perion Network Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Perion Network Ltd., L=Tel Aviv, S=Tel Aviv, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
45F87694FE8D1984719796AEC8031DF4

File PE Metadata
Compilation timestamp:
3/15/2010 2:27:50 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:/u2urzh9xu/XkauHl+WuKYkoaleHXBLkMu:/utrzh9xOXkF+WmBawHNkMu

Entry address:
0xA7B1

Entry point:
E8, E3, FE, FF, FF, 33, C0, 50, 50, 50, 50, E8, BE, 2B, 00, 00, C3, 56, 57, 8B, 7C, 24, 0C, 8B, F1, 8B, CF, 89, 3E, E8, D0, A7, FF, FF, 89, 46, 08, 89, 56, 0C, 8B, 87, 1C, 0C, 00, 00, 89, 46, 10, 5F, 8B, C6, 5E, C2, 04, 00, 8B, C1, 8B, 08, 8B, 50, 10, 3B, 91, 1C, 0C, 00, 00, 75, 0D, 6A, 00, FF, 70, 0C, FF, 70, 08, E8, AF, AC, FF, FF, C3, 55, 8B, EC, 83, EC, 1C, 56, 33, F6, 56, 56, 56, 56, 8D, 45, E4, 50, FF, 15, 40, 22, 41, 00, 85, C0, 74, 21, 56, 56, 56, 8D, 45, E4, 50, FF, 15, 44, 22, 41, 00, 8D, 45, E4...
 
[+]

Entropy:
7.5645

Code size:
66 KB (67,584 bytes)

The file CCleaner.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ude.databssint.com  (107.22.223.150:80)

TCP (HTTP):
Connects to storage.stgbssint.com  (172.229.236.170:80)

Remove CCleaner.exe - Powered by Reason Core Security