dca-monitoring.exe

Compete DCA Monitoring Tool

Compete Inc

The application dca-monitoring.exe by Compete Inc has been detected as a potentially unwanted program by 5 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. While running, it connects to the Internet address unallocated.barefruit.co.uk on port 443.
Publisher:
Compete, Inc.  (signed by Compete Inc)

Product:
Compete DCA Monitoring Tool

Version:
3.2.0.707

MD5:
8d50840f4f656979553456548c3d4cce

SHA-1:
2a8212b111f6c7e4ecc5f64ebb0cf81049486607

SHA-256:
be6705bc39bba9c3741b16c1cd64b59bcdd29852e005c23c1df3fa272c97cfa7

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
9/26/2017 1:43:20 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Task.Compete
15.3.6.5

Trend Micro House Call
Suspicious_GEN.F47V0301
7.2.65

VIPRE Antivirus
Compete
38154

File size:
1.1 MB (1,138,208 bytes)

Product version:
3.2.0.707

Copyright:
(c) Compete, Inc. All rights reserved.

Original file name:
dca-monitoring.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\consumer input\monitoring\dca-monitoring.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
12/21/2014 7:00:00 PM

Valid to:
3/22/2018 7:59:59 PM

Subject:
CN=Compete Inc, O=Compete Inc, L=Boston, S=Massachusetts, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0A6DDD60D9E6C4FAA56565923F8669C2

File PE Metadata
Compilation timestamp:
2/26/2015 5:31:54 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:9wOwsz43mOgr/8ZcW94H9k4P648h2WYP+7ajsZyT8M:yOB43Qw2jSnhPYP+0sZ+8M

Entry address:
0x9DE7C

Entry point:
E8, AC, AA, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 66, 8B, 08, 83, C0, 02, 66, 85, C9, 75, F5, 2B, 45, 08, D1, F8, 48, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 4D, 0C, 0F, B7, 11, 56, 8B, 75, 08, 0F, B7, 06, 2B, C2, 57, 75, 15, 2B, F1, 66, 85, D2, 74, 0E, 83, C1, 02, 0F, B7, 11, 0F, B7, 04, 0E, 2B, C2, 74, ED, 5F, 5E, 85, C0, 79, 05, 83, C8, FF, 5D, C3, 7E, 03, 33, C0, 40, 5D, C3, 8B, FF, 55, 8B, EC, 51, 83, 65, FC, 00, 56, 8D, 45, FC, 50, FF, 75, 0C, FF, 75, 08, E8, CF, AA, 00, 00, 8B, F0, 83...
 
[+]

Entropy:
6.5558

Code size:
782 KB (800,768 bytes)

Scheduled Task
Task name:
CIMT_daily_SID

Trigger:
Daily (Runs daily at 4:51 AM)

Action:
dca-monitoring.exe \daily

Description:
Updates Consumer Input CIIE activity status.


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP SSL):
Connects to unallocated.barefruit.co.uk  (92.242.140.21:443)

Remove dca-monitoring.exe - Powered by Reason Core Security