monitor.exe

We Build Toolbars LLC

The application monitor.exe by We Build Toolbars has been detected as a potentially unwanted program by 4 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Mutual Monitor”.
Publisher:
We Build Toolbars LLC  (signed and verified)

MD5:
0f068f3591c1418708f77b424e825648

SHA-1:
0fcf6f43be2cafa35d086b0afcb8cd7e85770788

SHA-256:
caaab1e0b1ece9f5f150b092d3bbce74a3dd573cdfdcf0e8bfbf8966ed66353e

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 6:53:59 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.WBTMonitor
2013.12.10

IKARUS anti.virus
Trojan.Win64
t3scan.2.2.29

Malwarebytes
PUP.Optional.WBTMonitor
v2013.12.20.10

Reason Heuristics
PUP.Optional.Service.WeBuildToolbars.H
14.3.2.15

File size:
627.1 KB (642,104 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\mutualpublic\monitor.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/7/2013 1:00:00 AM

Valid to:
3/4/2016 11:59:59 PM

Subject:
CN=We Build Toolbars LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=We Build Toolbars LLC, L=Las Vegas, S=Nevada, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4321DE10738278B93683CA542407F103

File PE Metadata
Compilation timestamp:
11/9/2013 12:08:34 AM

OS version:
5.1

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
11.0

CTPH (ssdeep):
12288:3fD7HdYX5oU9Ycl/V0HOKIiDk6g6eiBuo6:vD7HsLYS0uybgtiAx

Entry address:
0x44344

Entry point:
48, 83, EC, 28, E8, 13, 36, 01, 00, 48, 83, C4, 28, E9, 42, FE, FF, FF, CC, CC, 48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 63, D9, 48, 8D, 3D, D4, FE, 04, 00, 48, 03, DB, 48, 83, 3C, DF, 00, 75, 11, E8, A9, 00, 00, 00, 85, C0, 75, 08, 8D, 48, 11, E8, C1, E9, FF, FF, 48, 8B, 0C, DF, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, 48, FF, 25, BC, 3E, 02, 00, 48, 89, 5C, 24, 08, 48, 89, 6C, 24, 10, 48, 89, 74, 24, 18, 57, 48, 83, EC, 20, BF, 24, 00, 00, 00, 48, 8D, 1D, 84, FE, 04, 00, 8B, EF, 48, 8B, 33, 48, 85, F6...
 
[+]

Code size:
410.5 KB (420,352 bytes)

Service
Display name:
Mutual Monitor

Type:
Win32OwnProcess


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-54-235-215-251.compute-1.amazonaws.com  (54.235.215.251:80)

Remove monitor.exe - Powered by Reason Core Security