java.exe

The application java.exe has been detected as a potentially unwanted program by 32 anti-malware scanners. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. The file has been seen being downloaded from www.lpcloudsvr203.com.
MD5:
a8352e83caea79fe57ca2a0da2937a53

SHA-1:
6fa6f2ffe4e58542cc9afa02a3f21746182b97ca

SHA-256:
e9eb8629fb518c63743c74accc0dd31607f2fbf72886744323a640db35aeded2

Scanner detections:
32 / 68

Status:
Potentially unwanted

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Analysis date:
4/19/2024 7:10:39 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11027877
922

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
2014.07.22

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

avast!
Win32:DomaIQ-CC [PUP]
140617-1

AVG
Adware DomaIQ.X
2015.0.3400

Bitdefender
Trojan.Generic.11027877
1.0.20.1045

Clam AntiVirus
Win.Adware.Domaiq-45
0.98/19168

Comodo Security
Application.Win32.DomaIQ.PUT
18930

Dr.Web
Trojan.Damaged.1
9.0.1.05190

Emsisoft Anti-Malware
Trojan.Generic.11027877
8.14.07.28.08

ESET NOD32
Win32/DomaIQ.BB potentially unwanted application
8.7.0.302.0

F-Prot
W32/DomaIQ.E.gen
v6.4.7.1.166

F-Secure
Trojan.Generic.11027877
11.2014-28-07_2

G Data
Trojan.Generic.11027877
14.7.24

IKARUS anti.virus
AdWare.Lollipop
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.181.12795

Kaspersky
not-a-virus:AdWare.Win32.Lollipop
14.0.0.3493

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.07.28.08

McAfee
CryptDomaIQ
5600.7056

Microsoft Security Essentials
Threat.Undefined
1.179.723.0

MicroWorld eScan
Trojan.Generic.11027877
15.0.0.627

NANO AntiVirus
Riskware.Win32.Downware.cvxwqj
0.28.2.60990

nProtect
Trojan-Clicker/W32.Lollipop.389256
14.07.21.01

Panda Antivirus
PUP/MultiToolbar.A
14.07.28.08

Quick Heal
Adware.DomaIQ.BT5
7.14.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
14.7.28.8

Rising Antivirus
PE:Malware.DomaIQ!6.15EA
23.00.65.14726

Sophos
DomainIQ pay-per install
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10456

Vba32 AntiVirus
BScope.Downware.DomaIQ
3.12.26.3

VIPRE Antivirus
Threat.4783235
31208

File size:
382.5 KB (391,680 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\java.exe

File PE Metadata
Compilation timestamp:
3/6/2014 3:25:20 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:GSI5kqTzKQSzyQoR/M+634/ZaKszyR8Qbti28W/VYP:ApTz9SWQoR/Mb4VszyRi29/e

Entry address:
0x30ED

Entry point:
E8, B2, 3B, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3...
 
[+]

Entropy:
6.2526

Code size:
55 KB (56,320 bytes)

The file java.exe has been seen being distributed by the following URL.

Remove java.exe - Powered by Reason Core Security