panda_url_filtering.exe

Anti-phishing Domain Advisor (Powered by Panda Security)

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application panda_url_filtering.exe by Visicom Media has been detected as a potentially unwanted program by 4 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Panda Security URL Filtering’. This file is typically installed with the program Panda Security URL Filtering by Panda Security.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
Anti-phishing Domain Advisor (Powered by Panda Security)

Version:
1, 0, 0, 0

MD5:
c32d65ace833c78af7bce6959329fc87

SHA-1:
f18068806be3b5556b5e200195ce3776dda216e5

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 11:02:36 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.2945

Bkav FE
W32.HfsAdware
1.3.0.7237

Dr.Web
Tool.InstallToolbar.174
9.0.1.0298

Reason Heuristics
PUP.Visicom.VisicomMedia (M)
15.10.25.23

File size:
248.5 KB (254,472 bytes)

Product version:
1.0

Copyright:
Copyright (C) 2015 Visicom Media Inc.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\panda security url filtering\panda_url_filtering.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/8/2015 6:00:00 PM

Valid to:
2/8/2017 5:59:59 PM

Subject:
CN=Visicom Media Inc., OU=Visicom Media Inc., O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0F7022688814C950B353E71B8D1C1D84

File PE Metadata
Compilation timestamp:
5/3/2014 10:55:35 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:yIVe895ZHHxxx3FRdYSIZ+iNPjloDaqMwk2uC:hZHHxxx3zOSIwiNPjZwl

Entry address:
0x1312E

Entry point:
E8, 4C, 8D, 00, 00, E9, 78, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D...
 
[+]

Entropy:
6.3363

Code size:
143.5 KB (146,944 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Panda Security URL Filtering

Command:
"C:\Program Files\panda security url filtering\panda_url_filtering.exe"


The file panda_url_filtering.exe has been discovered within the following program.

Panda Security URL Filtering  by Panda Security
The Panda Security Toolbar is a free optional toolbar that comes with Panda Cloud. The toolbar provides web filtering along with some features that may come in handy for users. The toolbar works on Internet Explorer and Firefox only.
60% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to visicom-102.nationalnet.com  (69.50.130.33:80)

TCP (HTTP):
Connects to visicom-101.nationalnet.com  (69.50.130.31:80)

TCP (HTTP):
Connects to cache.google.com  (212.188.15.99:80)

TCP (HTTP):
Connects to algartelecom-ula001.cache.google.com  (201.16.134.98:80)

TCP (HTTP):
Connects to 201-048-053-039.static.ctbc.com.br  (201.48.53.39:80)

TCP (HTTP):
Connects to 201-048-053-038.static.ctbc.com.br  (201.48.53.38:80)

Remove panda_url_filtering.exe - Powered by Reason Core Security