Client.exe

Joltlogic

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application Client.exe by Joltlogic has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. This executable runs as a local area network (LAN) Internet proxy server listening on port 55620 and has the ability to intercept and modify all inbound and outbound Internet traffic on the local host.
Publisher:
Joltlogic  (signed and verified)

Version:
1.0.5462.26099

MD5:
b9f7ca1381f773fe4d142799553c89d4

SHA-1:
36505234434cb901ff9af075a3005c27fa9f25e8

SHA-256:
d791ddcdf680eb56e502287b9c7d5ae4da15c39cd0c28599b4208cf05aed88cd

Scanner detections:
7 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 12:29:20 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:IBryte-FV [PUP]
150102-1

AVG
Generic
2016.0.3219

Comodo Security
ApplicUnwnt
20595

ESET NOD32
MSIL/Adware.iBryte.F application
7.0.302.0

Reason Heuristics
PUP.Joltlogic.G
14.12.15.23

Trend Micro House Call
Suspicious_GEN.F47V1216
7.2.25

VIPRE Antivirus
Threat.4798837
36694

File size:
853.4 KB (873,832 bytes)

Product version:
1.0.5462.26099

Original file name:
Client.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\geniusbox\client.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/15/2014 5:00:00 PM

Valid to:
7/16/2015 4:59:59 PM

Subject:
CN=Joltlogic, O=Joltlogic, STREET=4600 Madison Ave FL 10, L=Kansas City, S=Missouri, PostalCode=64112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5EE011413A702F6705B25B34B674F3AB

File PE Metadata
Compilation timestamp:
12/15/2014 6:30:22 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:6jSsYG5rzHnT8bwxPULoGaryiJ64SeuBJdTs6JStdDszO56M:6jNYG5rzz8bwxPUhEduBJC6JSzcO

Entry address:
0xD59E6

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, D0, 02, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 38, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 50, 00, 00, 00, 5C, 60, 0D, 00, 74, 02, 00, 00, 00, 00, 00, 00, 74, 02, 34, 00, 00, 00, 56, 00, 53, 00...
 
[+]

Entropy:
6.3493

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
846.5 KB (866,816 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:55620/

Local host port:
55620

Default credentials:
No


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to cloud.gti.mcafee.com  (161.69.92.6:443)

TCP (HTTP SSL):
Connects to msnbot-65-55-252-43.search.msn.com  (65.55.252.43:443)

TCP (HTTP SSL):
Connects to edge-star-shv-10-dfw1.facebook.com  (31.13.66.144:443)

TCP (HTTP SSL):
Connects to dfw06s41-in-f4.1e100.net  (173.194.115.68:443)

Remove Client.exe - Powered by Reason Core Security