lud.exe

Lud

The application lud.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named 26792337 triggered to execute each time a user logs in. While running, it connects to the Internet address cdce.dal003.internap.com on port 80 using the HTTP protocol.
Publisher:
Lud

Product:
Lud

Version:
1.9.7.53

MD5:
1e0c9154360aa6cb68a50999d81d2d0d

SHA-1:
48fef1734e0e1a778f20c968ac6b4d2489361c1d

SHA-256:
e57d65a9fadc7c553646bdf648d83dc7a0e3a8409280beafa78d88ff0cb2b663

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 7:10:35 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/Adware.Dotdo.AP application
6.3.12010.0

Reason Heuristics
Adware.Dotdo.ET (M)
17.1.30.10

File size:
8.5 KB (8,704 bytes)

Product version:
1.9.7.53

Copyright:
Copyright © Lud 2017

Trademarks:
© 2017 Lud

Original file name:
lud.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\ml\lud.exe

File PE Metadata
Compilation timestamp:
1/30/2017 1:33:40 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x363E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.2656

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
6 KB (6,144 bytes)

Scheduled Task
Task name:
26792337

Trigger:
Logon (Runs on logon)

Description:
2679233726792337


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to static.hosted-by.miamidedicated.com  (162.222.193.17:80)

TCP (HTTP):
Connects to hosted-by.instantdedicated.com  (188.95.50.96:80)

TCP (HTTP):
Connects to server-54-230-141-254.sfo5.r.cloudfront.net  (54.230.141.254:80)

TCP (HTTP):
Connects to eb.83.1732.ip4.static.sl-reverse.com  (50.23.131.235:80)

TCP (HTTP):
Connects to px-acs001.quantserve.com.akadns.net  (64.95.32.31:80)

TCP (HTTP):
Connects to map2.hwcdn.net  (205.185.216.42:80)

TCP (HTTP):
Connects to lb-web.ustream.tv  (199.66.238.211:80)

TCP (HTTP):
Connects to 162-254-148-148.static.hvvc.us  (162.254.148.148:80)

TCP (HTTP):
Connects to cdce.dal003.internap.com  (74.201.53.200:80)

TCP (HTTP):
Connects to server-52-84-239-183.sfo5.r.cloudfront.net  (52.84.239.183:80)

TCP (HTTP SSL):
Connects to server-52-84-239-238.sfo5.r.cloudfront.net  (52.84.239.238:443)

TCP (HTTP):
Connects to ec2-52-86-129-112.compute-1.amazonaws.com  (52.86.129.112:80)

TCP (HTTP):
Connects to ec2-52-41-244-179.us-west-2.compute.amazonaws.com  (52.41.244.179:80)

TCP (HTTP SSL):
Connects to ec2-52-15-124-187.us-east-2.compute.amazonaws.com  (52.15.124.187:443)

TCP (HTTP):
Connects to ec2-34-200-134-167.compute-1.amazonaws.com  (34.200.134.167:80)

TCP (HTTP):
Connects to ec2-34-199-235-54.compute-1.amazonaws.com  (34.199.235.54:80)

TCP (HTTP):
Connects to ec2-34-194-23-195.compute-1.amazonaws.com  (34.194.23.195:80)

TCP (HTTP):
Connects to 68-233-228-20.static.hvvc.us  (68.233.228.20:80)

TCP (HTTP SSL):
Connects to 57.247.178.107.bc.googleusercontent.com  (107.178.247.57:443)

TCP (HTTP):
Connects to 108-61-16-186.constant.com  (108.61.16.186:80)

Remove lud.exe - Powered by Reason Core Security