contextualregisterscreenshot.exe

The application contextualregisterscreenshot.exe has been detected as a potentially unwanted program by 5 anti-malware scanners. This executable runs as a local area network (LAN) Internet proxy server listening on port 14885 and has the ability to intercept and modify all inbound and outbound Internet traffic on the local host. While running, it connects to the Internet address pub3.sky.fm on port 80 using the HTTP protocol.
MD5:
abb03906c76d2949e50e763ff05ca511

SHA-1:
928a7760e6f7e69579a4a37716ad30510e89619c

SHA-256:
78ac89dfa2231bb57e51dacc3e3678edda0283c7abf62b677d663e166d0a7f8c

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 3:10:47 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.PirritSuggestor
2014.06.05

avast!
Win32:PirritSuggestor-B [Adw]
2014.9-140604

Baidu Antivirus
Adware.Win32.Pirrit
4.0.3.1464

ESET NOD32
Win32/AdWare.Pirrit (variant)
8.9892

Panda Antivirus
Trj/Genetic.gen
14.06.04.02

File size:
287.5 KB (294,400 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\594c6b63a4513d9ad399488e76604da7\contextualregisterscreenshot.exe

File PE Metadata
Compilation timestamp:
6/3/2014 4:33:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.23

CTPH (ssdeep):
6144:AyI7yBJiXiQ+04LvGY5MEypGLETT+9vlay3XJbB0McTrEt3+b:AyhBJZXwpGLET4vlT3X30f

Entry address:
0x1590

Entry point:
83, EC, 1C, C7, 04, 24, 02, 00, 00, 00, FF, 15, 20, 69, 44, 00, E8, DB, FB, FF, FF, 8D, 74, 26, 00, 8D, BC, 27, 00, 00, 00, 00, A1, 4C, 69, 44, 00, FF, E0, 89, F6, 8D, BC, 27, 00, 00, 00, 00, A1, 40, 69, 44, 00, FF, E0, 90, 90, 90, 90, 90, 90, 90, 90, 90, 55, 89, E5, 83, EC, 18, C7, 04, 24, 00, A0, 43, 00, E8, 16, 6D, 02, 00, BA, 68, 6A, 42, 00, 83, EC, 04, 85, C0, 74, 15, C7, 44, 24, 04, 13, A0, 43, 00, 89, 04, 24, E8, 02, 6D, 02, 00, 83, EC, 08, 89, C2, 85, D2, 74, 11, C7, 44, 24, 04, 08, 50, 44, 00, C7...
 
[+]

Code size:
223.5 KB (228,864 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:14885/

Local host port:
14885

Default credentials:
No


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-208-30-101.compute-1.amazonaws.com  (54.208.30.101:80)

TCP (HTTP):
Connects to www.comodo.com  (91.199.212.176:80)

TCP (HTTP):
Connects to wikispaces.com  (208.43.192.33:80)

TCP (HTTP):
Connects to wi-in-f102.1e100.net  (173.194.67.102:80)

TCP (HTTP):
Connects to track-eu.adform.net  (85.235.246.3:80)

TCP (HTTP):
Connects to srv58-134-240-87.vk.com  (87.240.134.58:80)

TCP (HTTP):
Connects to srv117-131-240-87.vk.com  (87.240.131.117:80)

TCP (HTTP):
Connects to server-54-230-90-248.ind6.r.cloudfront.net  (54.230.90.248:80)

TCP (HTTP):
Connects to server-54-230-90-225.ind6.r.cloudfront.net  (54.230.90.225:80)

TCP (HTTP):
Connects to server-54-230-35-18.stl2.r.cloudfront.net  (54.230.35.18:80)

TCP (HTTP):
Connects to server-54-230-34-208.stl2.r.cloudfront.net  (54.230.34.208:80)

TCP (HTTP):
Connects to server-54-230-33-240.stl2.r.cloudfront.net  (54.230.33.240:80)

TCP (HTTP):
Connects to server-205-251-253-168.ind6.r.cloudfront.net  (205.251.253.168:80)

TCP (HTTP):
Connects to r1.ycpi.vip.ne1.yahoo.net  (98.138.81.72:80)

TCP (HTTP):
Connects to r1.ycpi.vip.ir2.yahoo.net  (217.12.13.40:80)

TCP (HTTP):
Connects to pub3.sky.fm  (70.42.73.189:80)

TCP (HTTP):
Connects to ord08s12-in-f25.1e100.net  (74.125.225.25:80)

TCP (HTTP):
Connects to muc03s01-in-f25.1e100.net  (173.194.35.153:80)

TCP (HTTP):
Connects to muc03s01-in-f13.1e100.net  (173.194.35.141:80)

TCP (HTTP):
Connects to mrs02s05-in-f3.1e100.net  (173.194.35.99:80)

Remove contextualregisterscreenshot.exe - Powered by Reason Core Security