panda_url_filtering.exe

Anti-phishing Domain Advisor (Powered by Panda Security)

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application panda_url_filtering.exe by Visicom Media has been detected as a potentially unwanted program by 5 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Panda Security URL Filtering’. While running, it connects to the Internet address visicom-102.nationalnet.com on port 80 using the HTTP protocol.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
Anti-phishing Domain Advisor (Powered by Panda Security)

Version:
1, 0, 0, 0

MD5:
129feefab129bad68d9476bf0cc3208a

SHA-1:
4a7f5ee5d8e15b4e015bd22f5edff32ceb6b6f59

SHA-256:
7617a9a5cbded193b797284c913f649ec69a80434cd776e8dba80f0c731e6863

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 1:58:10 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.3082

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Tool.InstallToolbar.174
9.0.1.0162

Reason Heuristics
PUP.Visicom.VisicomMedia
15.6.11.9

Trend Micro House Call
Suspicious_GEN.F47V0602
7.2.162

File size:
248.5 KB (254,472 bytes)

Product version:
1.0

Copyright:
Copyright (C) 2015 Visicom Media Inc.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\panda security url filtering\panda_url_filtering.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/9/2015 1:00:00 AM

Valid to:
2/9/2017 12:59:59 AM

Subject:
CN=Visicom Media Inc., OU=Visicom Media Inc., O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0F7022688814C950B353E71B8D1C1D84

File PE Metadata
Compilation timestamp:
5/3/2014 5:55:35 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:0IVe895ZHHxxx3FRdYSIZ+iNPjloDaqMwk2uY:7ZHHxxx3zOSIwiNPjZwr

Entry address:
0x1312E

Entry point:
E8, 4C, 8D, 00, 00, E9, 78, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D...
 
[+]

Code size:
143.5 KB (146,944 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Panda Security URL Filtering

Command:
"C:\ProgramData\panda security url filtering\panda_url_filtering.exe"


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to visicom-102.nationalnet.com  (69.50.130.33:80)

TCP (HTTP):
Connects to visicom-101.nationalnet.com  (69.50.130.31:80)

TCP (HTTP):
Connects to a92-122-216-65.deploy.akamaitechnologies.com  (92.122.216.65:80)

TCP (HTTP):
Connects to a92-122-216-54.deploy.akamaitechnologies.com  (92.122.216.54:80)

TCP (HTTP):
Connects to a84-53-146-97.deploy.akamaitechnologies.com  (84.53.146.97:80)

TCP (HTTP):
Connects to a72-247-210-19.deploy.akamaitechnologies.com  (72.247.210.19:80)

Remove panda_url_filtering.exe - Powered by Reason Core Security