myradioplayer.Service.exe

altanov.Service

myradioplayer

This is part of the Sendori web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application myradioplayer.Service.exe by myradioplayer has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “myradioplayerV2”.
Publisher:
altanov  (signed by myradioplayer)

Product:
altanov.Service

Version:
3.0.1.0

MD5:
2a313e41752a1c610c0f6983d83d8aff

SHA-1:
d0aee82c98db04c596fd87ff661be68523576afd

SHA-256:
8a1fd3333f9fa2df7c02d8844263b5fad20ae796f5f279b31a79d657e36f14ed

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 5:44:40 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Service.myradioplayer.U
14.12.18.11

File size:
21.7 KB (22,264 bytes)

Product version:
3.0.1.0

Copyright:
Copyright © altanov 2012

Original file name:
myradioplayer.Service.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\myradioplayer\myradioplayer.service.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/14/2014 8:00:00 PM

Valid to:
8/14/2017 7:59:59 PM

Subject:
CN=myradioplayer, O=myradioplayer, L=San Leandro, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
42911589C907180DE25AE153A05008F6

File PE Metadata
Compilation timestamp:
10/16/2014 4:49:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:ceqndZCCzYHeGmSiyh0ZGnE9kxUZA+tV23hnYPLcGAseMi:cdzzYHeGmFyhg95A+tg3hsS

Entry address:
0x551E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.0850

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
13.5 KB (13,824 bytes)

Service
Display name:
myradioplayerV2

Description:
Service myradioplayer.

Type:
Win32OwnProcess

Depends on:
WINMGMT


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-184-72-59-219.us-west-1.compute.amazonaws.com  (184.72.59.219:80)

TCP (HTTP):
Connects to server-52-84-141-16.yto50.r.cloudfront.net  (52.84.141.16:80)

TCP (HTTP):
Connects to ec2-184-169-155-248.us-west-1.compute.amazonaws.com  (184.169.155.248:80)

TCP (HTTP):
Connects to server-54-230-51-67.jfk5.r.cloudfront.net  (54.230.51.67:80)

TCP (HTTP):
Connects to server-54-192-87-180.lax3.r.cloudfront.net  (54.192.87.180:80)

TCP (HTTP):
Connects to server-54-192-75-126.hkg50.r.cloudfront.net  (54.192.75.126:80)

TCP (HTTP):
Connects to server-54-192-7-151.dfw3.r.cloudfront.net  (54.192.7.151:80)

TCP (HTTP):
Connects to server-52-85-94-143.jfk5.r.cloudfront.net  (52.85.94.143:80)

TCP (HTTP):
Connects to server-52-85-77-72.lax3.r.cloudfront.net  (52.85.77.72:80)

TCP (HTTP):
Connects to server-52-85-151-28.hkg51.r.cloudfront.net  (52.85.151.28:80)

TCP (HTTP):
Connects to ec2-54-241-10-57.us-west-1.compute.amazonaws.com  (54.241.10.57:80)

TCP (HTTP):
Connects to ec2-50-18-54-58.us-west-1.compute.amazonaws.com  (50.18.54.58:80)

TCP (HTTP):

TCP (HTTP):

Remove myradioplayer.Service.exe - Powered by Reason Core Security