lookthisupuninstall.exe

Installer

Sea Bug

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application lookthisupuninstall.exe by Sea Bug has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program LookThisUp by Sea Bug, LLC which is a potentially unwanted software program. The file has been seen being downloaded from d32k27yvyi4kmv.cloudfront.net. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
Sea Bug  (signed and verified)

Product:
Installer

Version:
1.0.0.0

MD5:
4a2d3423b7ad290a91bcf0ab0d06fe68

SHA-1:
6d0223b92d8734a6fe388b7de4e202f8c3d75df6

SHA-256:
6dc7079a2b0456eff723d8ffc6a99eafa5723d89f24aa6b67e01cfe968927b39

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Belongs to the Sambreel/Yontoo progam that inserts various forms of advertising in the user's web browser, installed with minimal or no user consent.

Analysis date:
5/8/2024 6:32:28 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo.SeaBug.Installer (M)
16.2.28.23

File size:
201.6 KB (206,480 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\lookthisup\lookthisupuninstall.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
7/25/2014 3:59:04 PM

Valid to:
7/25/2015 3:59:04 PM

Subject:
CN=Sea Bug, O=Sea Bug, L=Orange, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
081CF04D6E5726

File PE Metadata
Compilation timestamp:
9/19/2014 1:03:32 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:a9YOIDfHsesBK7VdXmXbQiVpAlfSS+hfOt:SYNDvsnBAdW3AkJ9I

Entry address:
0x30FBE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 14, 11, 00, 80, 10, 00, 00, 00, 64, 11, 00, 80, 18, 00, 00, 00, 50, 14, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6003

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
188 KB (192,512 bytes)

The file lookthisupuninstall.exe has been discovered within the following program.

LookThisUp  by Sea Bug, LLC
LookThisUp is an adware Internet extension that will inject advertisements to the browser on web pages that are not affiliated with the ads or the extension. Ads will be places as new ads that would not normally appear.
lookthisup.net
82% remove it
 
Powered by Should I Remove It?

The file lookthisupuninstall.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove lookthisupuninstall.exe - Powered by Reason Core Security