panda_url_filteringd.sys

Anti-phishing Domain Advisor

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The file panda_url_filteringd.sys, “Visicom Media Anti-phishing Domain Advisor (Powered by Panda Security)” by Visicom Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a Windows 64-bit kernel mode device driver named “panda_url_filteringd driver”.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
Anti-phishing Domain Advisor

Description:
Visicom Media Anti-phishing Domain Advisor (Powered by Panda Security)

Version:
2, 0, 0, 0

MD5:
1e25e271140605a3b62a7ce635b5dab9

SHA-1:
10e3ba99fe86818ce01a59724d9a5a093e1062e7

SHA-256:
8283020c31f595e17f28c0604e012fee2f646306e11a4bb2269ee7216bfea9d8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/19/2024 1:33:26 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.VisicomMedia.X
14.10.1.11

File size:
46.6 KB (47,704 bytes)

Product version:
2.0

Copyright:
Copyright (C) 2013 Visicom Media Inc.

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\ProgramData\panda security url filtering\panda_url_filteringd.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/8/2013 6:44:29 AM

Valid to:
11/9/2014 6:44:29 AM

Subject:
E=sysadmin@vmn.net, CN=Visicom Media Inc., O=Visicom Media Inc., L=Brossard, S=Quebec, C=CA

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11211539982821E53DCB554103CE4CFB4C45

File PE Metadata
Compilation timestamp:
11/20/2013 3:52:33 PM

OS version:
6.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
11.0

CTPH (ssdeep):
768:HqPs+WlKBELY4yHQDVUa64Yy2/i5gP6DNtwmBML7CcCxpV92D8fgQPrIiy:HA44JQce2B6Qm9cCjV9zPby

Entry address:
0xC070

Entry point:
48, 89, 5C, 24, 08, 57, 48, 83, EC, 20, 48, 8B, DA, 48, 8B, F9, E8, 83, FF, FF, FF, 48, 8B, D3, 48, 8B, CF, 48, 8B, 5C, 24, 30, 48, 83, C4, 20, 5F, E9, 6E, 4F, FF, FF, CC, CC, 50, C2, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 5C, C6, 00, 00, 60, 91, 00, 00, 40, C1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FE, C9, 00, 00, 50, 90, 00, 00, F0, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, F6, CA, 00, 00, 00, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.2699

Code size:
32 KB (32,768 bytes)

Driver
Display name:
panda_url_filteringd driver

Service name:
panda_url_filteringd

Type:
Kernel device driver (KernelDriver)


Remove panda_url_filteringd.sys - Powered by Reason Core Security