proc.exe

The application proc.exe has been detected as adware by 3 anti-malware scanners.
MD5:
a694180da7c9a463b28db094ef503aa7

SHA-1:
d8b55ac242954b6cd1e6ee4e6231fcd8e9a57523

SHA-256:
0eca9f6ca021bff7365a2bcf0f55d0b710abe9d9066ae5c5e0d1f5e046e38363

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
11/18/2017 6:38:07 PM UTC  (today)

Scan engine
Detection
Engine version

McAfee Web Gateway
BehavesLike.Win32.Downloader.gh
7.6875

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
Adware.50Red.Bench
15.1.25.8

File size:
477.5 KB (488,960 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\bench\proxy\proc.exe

File PE Metadata
Compilation timestamp:
1/16/2015 4:56:31 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:Kri98OfN5QOeUry1xGDpIzx/w80sLbTUAWmW+N+DyljR:h9jfrxyPGCx/VxLbTrWm1N+cj

Entry address:
0x3BA41

Entry point:
E8, 21, 1C, 01, 00, E9, 39, FE, FF, FF, 55, 8B, EC, 51, 53, 33, DB, 56, 39, 5D, 08, 75, 16, E8, CD, 0B, 00, 00, 6A, 16, 5E, 89, 30, E8, 14, 0B, 00, 00, 8B, C6, E9, 89, 00, 00, 00, 8B, 75, 0C, 85, F6, 74, E3, E8, 70, 3B, 00, 00, 85, C0, 75, 0D, FF, 15, 2C, 42, 46, 00, 85, C0, 75, 03, 33, DB, 43, 33, C0, 50, 50, 6A, FF, FF, 75, 08, 89, 06, 50, 53, FF, 15, A8, 40, 46, 00, 89, 45, FC, 85, C0, 75, 11, FF, 15, 64, 41, 46, 00, 50, E8, 58, 0B, 00, 00, 59, 33, C0, EB, 41, 03, C0, 50, E8, E7, 05, 00, 00, 89, 06, 59...
 
[+]

Code size:
396 KB (405,504 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-208-30-101.compute-1.amazonaws.com  (54.208.30.101:80)

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

Remove proc.exe - Powered by Reason Core Security