convertad.exe

The application convertad.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ConvertAd’. While running, it connects to the Internet address 208.43.241.178-static.reverse.softlayer.com on port 80 using the HTTP protocol.
Version:
1.0.0.1

MD5:
88022f6c2fee6c279e2f2f1737034f04

SHA-1:
9c26eac8f03121ba37c7a6481da3d19ff0df22cd

SHA-256:
9fccd941aa103e2d145bd39be4a119f5faeb740b3d5d304f0ed9d517e9c66ecf

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 8:58:44 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.957728
748

Agnitum Outpost
PUA.ConvertAd
7.1.1

avast!
Win32:Adware-CBV [PUP]
2014.9-150117

AVG
Generic6
2016.0.3226

Baidu Antivirus
Adware.Win32.ConvertAd
4.0.3.15117

Bitdefender
Application.Generic.957728
1.0.20.85

ESET NOD32
Win32/Adware.ConvertAd (variant)
9.10877

Fortinet FortiGate
Riskware/ConvertAd
1/17/2015

F-Secure
Application.Generic.957728
11.2015-17-01_7

G Data
Application.Generic.957728
15.1.24

IKARUS anti.virus
AdWare.MultiPlug
t3scan.1.8.5.0

K7 AntiVirus
Adware
13.187.14332

MicroWorld eScan
Application.Generic.957728
16.0.0.51

Reason Heuristics
Threat.Win.Reputation.IMP
15.1.17.19

Sophos
Generic PUA JM
4.98

Trend Micro House Call
Suspicious_GEN.F47V1208
7.2.17

File size:
2 MB (2,140,672 bytes)

Product version:
1.0.0.1

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\convertad\convertad.exe

File PE Metadata
Compilation timestamp:
11/18/2014 5:18:41 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:DFFYgixz5jr8z+JK4MUxMbCqNYCl5QCSJ6nmLHl2v1mxXWTk8lA5BBspE:RFYf5jr8KJaUACqNYCl5QCSJ6pv1mETR

Entry address:
0x148CAE

Entry point:
E8, C6, B4, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, E0, 90, 5D, 00, 75, 02, F3, C3, E9, 4D, B5, 00, 00, 8B, 41, 04, 85, C0, 75, 05, B8, B8, EC, 5A, 00, C3, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 57, 8B, F9, 74, 2D, 56, FF, 75, 08, E8, 05, 03, 00, 00, 8D, 70, 01, 56, E8, 1A, 18, 00, 00, 59, 59, 89, 47, 04, 85, C0, 74, 11, FF, 75, 08, 56, 50, E8, 13, B6, 00, 00, 83, C4, 0C, C6, 47, 08, 01, 5E, 5F, 5D, C2, 04, 00, 8B, FF, 56, 8B, F1, 80, 7E, 08, 00, 74, 09, FF, 76, 04, E8, AD, 17, 00, 00, 59, 83, 66, 04, 00, C6, 46...
 
[+]

Entropy:
6.4689

Code size:
1.5 MB (1,570,304 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ConvertAd

Command:
C:\users\{user}\appdata\local\convertad\convertad.exe


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 208.43.241.178-static.reverse.softlayer.com  (208.43.241.178:80)

Remove convertad.exe - Powered by Reason Core Security