passshowqev161.exe

The application passshowqev161.exe has been detected as adware by 5 anti-malware scanners. This executable runs as a local area network (LAN) Internet proxy server listening on port 14089 and has the ability to intercept and modify all inbound and outbound Internet traffic on the local host. This is part of the Revizer line of web browser extensions that inject 3rd-party advertisements in the user's web browser as well as setup a proxy server for the browser in order to track behaviors and display context based-ads from various partners (mostly adware).
MD5:
7722a2f6df6f3896cd9af5fd583a34a7

SHA-1:
ca7a55d07c037b8e06b7df1e99d3079303f2de57

SHA-256:
71d995c83da397b28979b31773287974124fba48338323b6a50baf64b9762af1

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
4/25/2024 3:38:24 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-BNS [PUP]
2014.9-140509

Baidu Antivirus
Adware.Win32.AddLyrics
4.0.3.1459

ESET NOD32
Win32/AdWare.AddLyrics.AK (variant)
8.9738

Qihoo 360 Security
Malware.QVM10.Gen
1.0.0.1015

Reason Heuristics
Adware.Revizer.O
14.5.9.1

File size:
139 KB (142,336 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\passshow\passshowqev161.exe

File PE Metadata
Compilation timestamp:
4/27/2014 1:47:32 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
1536:gg9qNIgtkvd98seMtji9561NLtUQJMG9ZxrpDiwuC8uu/kS/1/YqCskdXtYPB7Xf:f9vHdSsi956D3DMwuXJTIXtq10

Entry address:
0xBEC7

Entry point:
E8, BB, 58, 00, 00, E9, 95, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 80, 00, 00, 00, 72, 0E, 83, 3D, 60, 1E, 42, 00, 00, 74, 05, E9, 16, 59, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07...
 
[+]

Code size:
84 KB (86,016 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:14089/

Local host port:
14089

Default credentials:
No


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to a23-194-121-47.deploy.static.akamaitechnologies.com  (23.194.121.47:80)

TCP (HTTP):
Connects to tweakbit.com  (45.33.17.19:80)

TCP (HTTP):
Connects to ip198.27.106.242.torange.in  (198.27.106.242:80)

TCP (HTTP):
Connects to ec2-54-208-30-101.compute-1.amazonaws.com  (54.208.30.101:80)

Remove passshowqev161.exe - Powered by Reason Core Security