jueb56b.exe

Installer

The application jueb56b.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from 113.171.224.175 and multiple other hosts. While running, it connects to the Internet address www.ibbalance.com on port 443.
Product:
Installer

Description:
Installer-H

Version:
1.0.0.0

MD5:
62be2f8ad70e13dd8259cdd27f5553f6

SHA-1:
695c2960fea22b2fea1d72f51721d8bdff00b1a4

SHA-256:
ab6339c36adbf5f4420f8f7aa834d944fd1f1edb7d23f51c4c145b9e887c5dd0

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 1:39:40 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Adware/Win32.Imali
2015.04.13

Avira AntiVirus
TR/Dropper.MSIL.Gen
3.6.1.96

avast!
Win32:GenMaliciousA-IBX [PUP]
2014.9-150715

Baidu Antivirus
Adware.MSIL.Imali
4.0.3.15413

ESET NOD32
MSIL/Adware.Imali (variant)
9.11461

G Data
MSIL.Adware.OfferInstaller
15.4.25

herdProtect (fuzzy)
2015.7.15.5

IKARUS anti.virus
PUA.MSIL.Downloader
t3scan.1.8.9.0

File size:
2.9 MB (2,998,272 bytes)

Product version:
1.0.0.0

Original file name:
FinalInstaller_dotnet4.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\jueb56b.exe

File PE Metadata
Compilation timestamp:
4/12/2015 6:50:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:dqZFUs6kcZwzMgmjjTySlH4eBjMxXRhCs48:afXc+zXmOaH4eZMxP4

Entry address:
0x2D1F6E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.4432

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.8 MB (2,949,120 bytes)

The file jueb56b.exe has been seen being distributed by the following 2 URLs.

http://113.171.224.175/.../FinalInstaller_dotnet4.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove jueb56b.exe - Powered by Reason Core Security