ContentFinder.exe

ContentFinder

ContentFinder Software

The application ContentFinder.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. While running, it connects to the Internet address customer.worldstream.nl on port 80 using the HTTP protocol.
Publisher:
ContentFinder Software

Product:
ContentFinder

Version:
2.3.0.0

MD5:
4ee961b75309125138f90d0c4bdca2e8

SHA-1:
69451c7c35505c4554cb55695e44f47582bc0c6b

SHA-256:
2685f6b448f8462916a15f2a47ee290abf293c701cc148e0c053ec6f19714058

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
9/25/2017 4:36:46 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2497308
567

Agnitum Outpost
Riskware.Agent
7.1.1

Arcabit
Trojan.Generic.D261B1C
1.0.0.425

Baidu Antivirus
PUA.Win32.SoundFrost
4.0.3.15620

Bitdefender
Trojan.GenericKD.2497308
1.0.20.995

Emsisoft Anti-Malware
Trojan.GenericKD.2497308
8.15.07.18.04

ESET NOD32
Win32/SoundFrost.E potentially unwanted (variant)
9.11802

Fortinet FortiGate
Riskware/SoundFrost
7/18/2015

F-Secure
Trojan.GenericKD.2497308
11.2015-18-07_7

G Data
Trojan.GenericKD.2497308
15.7.25

K7 AntiVirus
Adware
13.205.16534

K7 Gateway Antivirus
Adware
13.205.16534

MicroWorld eScan
Trojan.GenericKD.2497308
16.0.0.597

nProtect
Trojan.GenericKD.2497308
15.07.10.01

Panda Antivirus
Generic Suspicious
15.07.18.04

Rising Antivirus
PE:Trojan.Win32.Generic.18DEF2F0!417264368
23.00.65.15716

Trend Micro House Call
Suspicious_GEN.F47V0617
7.2.171

Trend Micro
TROJ_GEN.R01TC0EG315
10.465.18

VIPRE Antivirus
Trojan.Win32.Generic
41938

File size:
163.5 KB (167,424 bytes)

Product version:
2.3.0.0

Copyright:
Copyright (C) 2010-2015

Original file name:
ContentFinder.exe

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\users\{user}\appdata\local\contentfinder.exe

File PE Metadata
Compilation timestamp:
5/19/2015 8:35:09 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:EPuQCkkqVtkIhjX7hHtOAaWPc8y+Jr12ZgjoJwPszceQ:EPRuqtkIhjX7hHtOAaW0LehATJpQ

Entry address:
0x3D42

Entry point:
E8, 8C, 04, 00, 00, E9, 63, FD, FF, FF, FF, 25, A8, 50, 40, 00, FF, 25, A4, 50, 40, 00, FF, 25, A0, 50, 40, 00, CC, CC, 68, B9, 3D, 40, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 60, A1, 40, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 8B, FF, 55, 8B, EC, FF, 75, 14, FF...
 
[+]

Entropy:
4.8432

Code size:
15.5 KB (15,872 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to customer.worldstream.nl  (217.23.7.144:80)

TCP (HTTP):
Connects to server31.worldstream.nl  (93.190.141.64:80)

TCP (HTTP):
Connects to 186-231-74-58.ded.intelignet.com.br  (186.231.74.58:80)

TCP (HTTP):
Connects to 186-231-74-55.ded.intelignet.com.br  (186.231.74.55:80)

TCP (HTTP SSL):
Connects to ec2-54-244-230-149.us-west-2.compute.amazonaws.com  (54.244.230.149:443)

TCP (HTTP):
Connects to 186-230-63-57.ded.intelignet.com.br  (186.230.63.57:80)

Remove ContentFinder.exe - Powered by Reason Core Security