IEError.exe

IEError

JH Software Private Limited

The application IEError.exe by JH Software Private Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program WeatherApp by JH Software Private Limited. While running, it connects to the Internet address cache.google.com on port 80 using the HTTP protocol.
Publisher:
JH Software Private Limited  (signed and verified)

Product:
IEError

Version:
1.0.0.0

MD5:
d1440a87ea6395b86a564914fe518b32

SHA-1:
1ae1f8fb3b97ddbfd5fb30f421e13a208b191cdf

SHA-256:
1e3e41786cbbc4f32c437839f6211ee07cc4f8f06fb8b73c6ff0c059cce655aa

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
9/24/2018 9:03:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.JHSoftwarePrivate
15.5.18.11

File size:
17.8 KB (18,176 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
IEError.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\portable weatherapp\ieerror.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/27/2014 6:00:00 PM

Valid to:
7/19/2015 5:59:59 PM

Subject:
CN=JH Software Private Limited, OU=IT, O=JH Software Private Limited, L=New Delhi, S=Delhi, C=IN

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1EB0D774DCDE92063F522689F4040A38

File PE Metadata
Compilation timestamp:
5/3/2015 11:47:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:EvtBaxyoi2wbUMxMCtqJMXMJYnAuSPLz3j:E1cscPJY8j

Entry address:
0x440E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.0384

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
9.5 KB (9,728 bytes)

The file IEError.exe has been discovered within the following program.

WeatherApp  by JH Software Private Limited
jhsoftware.in
50% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-72-9-51.eu-west-1.compute.amazonaws.com  (54.72.9.51:80)

TCP (HTTP):
Connects to cache.google.com  (208.117.231.153:80)

TCP (HTTP):
Connects to blk-237-125-22.eastlink.ca  (173.237.125.22:80)

Remove IEError.exe - Powered by Reason Core Security