guntony_server.exe

Shan Feng

The application guntony_server.exe by Shan Feng has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Update Service(Guntony_update)”. It runs as a scheduled task under the Windows Task Scheduler named GuntonyBrowserUpdateCore triggered daily at a specified time. While running, it connects to the Internet address server-52-84-246-80.sfo20.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
Shan Feng  (signed and verified)

Version:
50.14.2661.78

MD5:
fa2c5b35ca039d86f76911f711ca3f30

SHA-1:
00a2104437d1a088fc2dc1c238d0b97ea8c6040d

SHA-256:
b5a6fdbf3214809754c1d230d479387e141c82b3911d1e917e6cc531d313f3a2

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 12:42:42 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Elex (M)
16.6.26.12

File size:
462.4 KB (473,472 bytes)

Product version:
50.14.2661.78

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\guntony\guntony\bin\guntony_server.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
5/5/2016 7:00:00 PM

Valid to:
10/22/2016 6:59:59 PM

Subject:
CN=Shan Feng, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
5468DE414178163609F5122D532EB4F4

File PE Metadata
Compilation timestamp:
5/12/2016 3:06:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:lmkRH1eYBQ7wI3Zlhyr+D+9LK04jVkQzOZMfZYHP7c0ADEk8doior3VwAW2Ush:lm4H16wIJlhyKD+gBZKP72DWdoiB6Ph

Entry address:
0x35A92

Entry point:
E8, 20, 4E, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 30, C3, 46, 00, 75, 02, F3, C3, E9, C4, 13, 00, 00, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 4C, E8, 46, 00, FF, 15, 10, 82, 45, 00, 85, C0, 75, 18, 56, E8, 79, 55, 00, 00, 8B, F0, FF, 15, 5C, 82, 45, 00, 50, E8, 7E, 55, 00, 00, 59, 89, 06, 5E, 5D, C3, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 77, 6F, 53, 57, A1, 4C, E8, 46, 00, 85, C0, 75, 1D, E8, 51, 4B, 00, 00, 6A, 1E, E8, A7, 4B, 00, 00, 68, FF, 00, 00, 00, E8, 9C, 36, 00, 00, A1, 4C...
 
[+]

Entropy:
6.4585

Code size:
346.5 KB (354,816 bytes)

Scheduled Task
Task name:
GuntonyBrowserUpdateCore

Trigger:
Daily (Runs daily at 05:03 a.m.)

Description:
This task is used to update your Guntony Browser, which means you can use the latest version of Guntony Browser and fix a potential security hole.


Service
Display name:
Update Service(Guntony_update)

Service name:
Guntony_update

Description:
Keeps your Guntony software up to date. If this service is disabled or stopped, your Guntony software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and f

Type:
Win32OwnProcess

Depends on:
RpcSs


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-52-84-25-23.sea32.r.cloudfront.net  (52.84.25.23:80)

TCP (HTTP):
Connects to server-52-84-25-198.sea32.r.cloudfront.net  (52.84.25.198:80)

TCP (HTTP):
Connects to server-52-84-246-80.sfo20.r.cloudfront.net  (52.84.246.80:80)

Remove guntony_server.exe - Powered by Reason Core Security