police.story.2013.bdrip.x264.ac3playnow.mkv_tsv5ryz8.exe

1.3.9.0.140504.01

ClientConnect LTD

The file belongs to the ClientConnect (Conduit/Perion) platform, a utility that bundles and monetizes search toolbars and browser add-ons. The application police.story.2013.bdrip.x264.ac3playnow.mkv_tsv5ryz8.exe by ClientConnect has been detected as adware by 17 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from dm.dmccint.com and multiple other hosts. While running, it connects to the Internet address cms.dmccint.com on port 80 using the HTTP protocol.
Publisher:
ClientConnect LTD  (signed and verified)

Product:
1.3.9.0.140504.01

Description:
Setup.exe

Version:
1.3.9.0

MD5:
16a2a6a99d52bf3a55c23b47e95c675f

SHA-1:
e6423f6857f30818b6433f60fbec6131caa04ccc

SHA-256:
578727a110c3c64e2922cdd29923e0afa66af4b691987f07950aa59cf3adb8f5

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Analysis date:
4/26/2024 3:08:54 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Conduit
7.1.1

avast!
Win32:Adware-BRM [PUP]
2014.9-150123

AVG
Generic
2016.0.3220

Baidu Antivirus
Adware.Win32.Toolbar
4.0.3.15123

Dr.Web
Adware.Conduit.96
9.0.1.023

ESET NOD32
Win32/ClientConnect (variant)
9.10269

Fortinet FortiGate
Riskware/Toolbar_Conduit
1/23/2015

K7 AntiVirus
Trojan
13.183.13054

Kaspersky
not-a-virus:WebToolbar.Win32.Agent
14.0.0.2596

Malwarebytes
PUP.Optional.ClientConnect
v2015.01.23.05

McAfee
Artemis!16A2A6A99D52
5600.6876

NANO AntiVirus
Riskware.Win32.Conduit.dbqqxi
0.28.2.61519

Panda Antivirus
Trj/CI.A
15.01.23.05

Reason Heuristics
PUP.Installer.Conduit
15.1.23.17

Total Defense
Win32/Tnega.ALHeNWC
37.0.11126

Trend Micro House Call
Suspicious_GEN.F47V0814
7.2.23

VIPRE Antivirus
Conduit
32294

File size:
207.3 KB (212,264 bytes)

Product version:
1.3.9.0

Copyright:
© 2014 ClientConnect Ltd.

Original file name:
Police.Story.2013.BDRip.X264.AC3PLAYNOW.mkv.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\police.story.2013.bdrip.x264.ac3playnow.mkv_tsv5ryz8.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/3/2014 7:00:00 PM

Valid to:
2/5/2016 6:59:59 PM

Subject:
CN=ClientConnect LTD, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=DM4, O=ClientConnect LTD, L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
201C61613E36EF7DD163280196CD80F7

File PE Metadata
Compilation timestamp:
6/9/2012 9:19:49 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:Rz+92mhAMJ/cPl3iCKqozlx/LVXHSPF0Mfk:RK2mhAMJ/cPlmj7VXp

Entry address:
0xAC87

Entry point:
E8, E3, FE, FF, FF, 33, C0, 50, 50, 50, 50, E8, 9F, 30, 00, 00, C3, 56, 57, 8B, 7C, 24, 0C, 8B, F1, 8B, CF, 89, 3E, E8, 8F, AB, FF, FF, 89, 46, 08, 89, 56, 0C, 8B, 87, 24, 0C, 00, 00, 89, 46, 10, 5F, 8B, C6, 5E, C2, 04, 00, 8B, C1, 8B, 08, 8B, 50, 10, 3B, 91, 24, 0C, 00, 00, 75, 0D, 6A, 00, FF, 70, 0C, FF, 70, 08, E8, 0E, B1, FF, FF, C3, 56, 8B, F1, 8B, 06, 85, C0, 74, 07, 50, FF, 15, C4, 40, 41, 00, 83, 26, 00, 83, 66, 08, 00, 83, 66, 0C, 00, 5E, C3, 56, 8B, F1, 80, 7E, 04, 00, 75, 34, 68, F4, 44, 41, 00...
 
[+]

Entropy:
7.5157

Code size:
73 KB (74,752 bytes)

The file police.story.2013.bdrip.x264.ac3playnow.mkv_tsv5ryz8.exe has been seen being distributed by the following 2 URLs.

http://dm.dmccint.com//ThinDMDownload/ThinDMDownload.ashx?PublisherID=198&Setid=26&SoftwareName=Skype&SoftwareDownloadUrl=http://downloads.safestdownloads.com/skype.exe&ImageUrl=http://cdn.safestdownloads.com/resources/.../skype_1.png&SoftwareDescription=Calling, seeing, messaging and sharing with others – wherever they are.&PUID=1523566339190971506&PPD=search,45644069063,skype,e,,c,Skype,,,www.download-free-soft.net&FID=CKmL-PXsm8ACFbTm7AodxGUALA&InstallSessionID=15235663391909715063171265&CID=11131

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to cms.dmccint.com  (23.67.242.80:80)

 
http://cms.dmccint.com/DynamicOffer/16658638/16679761/?mainofferId=16655204&CurrentStep=2&TotalSteps=4&DownloadBrowser=IE&CType=-1&UserMode=-1&DMVersion=1.3.6.66.16678627.01&Language=US-EN