jetboostinstallbackwork.exe

BlueSprig, Inc.

The application jetboostinstallbackwork.exe by BlueSprig has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address server-54-192-37-210.jfk1.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
BlueSprig, Inc.  (signed and verified)

Version:
1.1.0.1

MD5:
3669de50fa7aa1a7820912e8e82c830b

SHA-1:
f1aa0c9935cc2b0244ef75b2356fb533b78fe84e

SHA-256:
301bf55f49f7c96c8c592ca495724de8b0d229a7dba24abadacbdaa00be853ee

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 12:42:43 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BlueSprig.X
14.12.16.10

File size:
585.3 KB (599,376 bytes)

Product version:
1.1.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\jetboostinstallbackwork.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/3/2011 3:00:00 AM

Valid to:
11/3/2013 2:59:59 AM

Subject:
CN="BlueSprig, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="BlueSprig, Inc.", L=San Fransisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
589D023EC02E552CDAA00B1FA0FDCA85

File PE Metadata
Compilation timestamp:
2/13/2012 9:11:29 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:8ga/+TBqtpJ01FlYe7fF7NiiWvWP1p2jeUEOQE888888888888W88888888888D:8v/+ToJ01FlYk3iiIY2jW2

Entry address:
0x759A4

Entry point:
55, 8B, EC, 83, C4, F0, B8, 2C, 49, 47, 00, E8, D8, 20, F9, FF, A1, C4, 7E, 47, 00, 8B, 00, E8, A4, 32, FF, FF, 6A, 00, A1, C4, 7E, 47, 00, 8B, 00, 8B, 80, 70, 01, 00, 00, 50, E8, 87, 2F, F9, FF, 8B, 0D, DC, 7F, 47, 00, A1, C4, 7E, 47, 00, 8B, 00, 8B, 15, 24, 45, 47, 00, E8, 8F, 32, FF, FF, A1, C4, 7E, 47, 00, 8B, 00, E8, D3, 33, FF, FF, E8, 6A, F2, F8, FF, 8B, C0, 00, 00, 00, 00, 00, 00, 00, 00, 02, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 32, 13, 8B, C0...
 
[+]

Entropy:
6.5127

Developed / compiled with:
Microsoft Visual C++

Code size:
465.5 KB (476,672 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-192-37-210.jfk1.r.cloudfront.net  (54.192.37.210:80)

TCP (HTTP):
Connects to qu-in-f139.1e100.net  (209.85.201.139:80)

Remove jetboostinstallbackwork.exe - Powered by Reason Core Security