itunes_tsv1a2xpc.exe

Perion Network Ltd.

The application itunes_tsv1a2xpc.exe by Perion Network has been detected as a potentially unwanted program by 11 anti-malware scanners. The program is a setup application that uses the Perion Download Manager installer. With this installer, users are expecting to download Apple's iTunes but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware. The file has been seen being downloaded from dm.dmccint.com and multiple other hosts. While running, it connects to the Internet address ude.databssint.com on port 80 using the HTTP protocol.
Publisher:
Perion Network Ltd.  (signed and verified)

MD5:
7049ff3c1c85c96f3f1746cf139401be

SHA-1:
895984af6675f2a56850accc5ca2d97ed84fddc7

SHA-256:
ad3e4a4ac50215f74a8b4e5dc13b361cd3010e5a166b079e30dc74c87eedd5ff

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
2/23/2020 12:22:22 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-gen [Adw]
2014.9-150205

Baidu Antivirus
PUA.Win32.Perinet
4.0.3.1525

Dr.Web
Adware.Downware.1895
9.0.1.036

ESET NOD32
Win32/Toolbar.Conduit.AE
9.10678

Fortinet FortiGate
Riskware/Toolbar_Conduit
2/5/2015

G Data
Win32.Application.Conduit
15.2.24

K7 AntiVirus
Unwanted-Program
13.185.13888

Kaspersky
not-a-virus:WebToolbar.Win32.Perinet
14.0.0.2531

Malwarebytes
PUP.Optional.ClientConnect
v2015.02.05.08

Reason Heuristics
PUP.Bundler.Perion
15.2.5.20

VIPRE Antivirus
Conduit
34552

File size:
641.9 KB (657,256 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Perion Download Manager (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\itunes_tsv1a2xpc.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/23/2012 7:00:00 PM

Valid to:
4/23/2015 6:59:59 PM

Subject:
CN=Perion Network Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Perion Network Ltd., L=Tel Aviv, S=Tel Aviv, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
45F87694FE8D1984719796AEC8031DF4

File PE Metadata
Compilation timestamp:
2/24/2012 1:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:9EsRtuGRKsf1TAEIklh+h/fwyR0qDGc2nDbO4K1YSqK6nWBX00h275:9jR8GRdqywh3BPCLnPO4K1Y33n+X1h65

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Entropy:
7.9621

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file itunes_tsv1a2xpc.exe has been seen being distributed by the following 10 URLs.

http://dm.dmccint.com//ThinDMDownload/ThinDMDownload.ashx?PublisherID=198&Setid=13&SoftwareName=iTunes&SoftwareDownloadUrl=http://allmyapps.com/binary/1397/213291/direct-download?token=0c63f9a06957d29e6d7681d8ecbcbe5aa816537e&ImageUrl=http://static.allmyapps.com/data/i/t/.../31c687d0d6b4d95e2be416e75b98b2f2_itunes.jpg&SoftwareDescription=Organize and play digital music and video&PUID=1523566062996618922&PPD=search,41357518167,itunes,e,,c,iTunes,,,www.soft-now.net&FID=CjkKEQjwlcSdBRD3wva3-KOAo80BEiQAjNIhieYz_whcMOiP1kxxwTBqNXwfZM8d2yTF_CNfuf03YGjw_wcB&InstallSessionID=152356606299661892283719864&CID=11078

http://dm.dmccint.com//ThinDMDownload/ThinDMDownload.ashx?PublisherID=198&Setid=13&SoftwareName=iTunes&SoftwareDownloadUrl=http://allmyapps.com/binary/1397/213291/direct-download?token=0c63f9a06957d29e6d7681d8ecbcbe5aa816537e&ImageUrl=http://static.allmyapps.com/data/i/t/.../31c687d0d6b4d95e2be416e75b98b2f2_itunes.jpg&SoftwareDescription=Organize and play digital music and video&PUID=1605756791256481024&PPD=search,42454281567,itunes,e,,c,iTunes,,,www.soft-now.net&FID=CPKj6YrisL8CFdOhtAodg1gAQA&InstallSessionID=1605756791256481024131339455&CID=11111

http://dm.dmccint.com//ThinDMDownload/ThinDMDownload.ashx?PublisherID=198&Setid=13&SoftwareName=iTunes&SoftwareDownloadUrl=http://allmyapps.com/binary/1397/213291/direct-download?token=0c63f9a06957d29e6d7681d8ecbcbe5aa816537e&ImageUrl=http://static.allmyapps.com/data/i/t/.../31c687d0d6b4d95e2be416e75b98b2f2_itunes.jpg&SoftwareDescription=Organize and play digital music and video&PUID=1523566079189748428&PPD=search,41357509767,itunes download,e,,c,iTunes,,,www.soft-now.net&FID=CIOdq8mxqL8CFQwQaQod90oARg&InstallSessionID=152356607918974842851528342&CID=11078

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ude.databssint.com  (107.22.223.150:80)

TCP (HTTP):
Connects to storage.stgbssint.com  (172.229.236.170:80)

Remove itunes_tsv1a2xpc.exe - Powered by Reason Core Security