re-markitxy161.exe

The application re-markitxy161.exe has been detected as adware by 19 anti-malware scanners. This executable runs as a local area network (LAN) Internet proxy server listening on port 14138 and has the ability to intercept and modify all inbound and outbound Internet traffic on the local host. This is part of the Revizer line of web browser extensions that inject 3rd-party advertisements in the user's web browser as well as setup a proxy server for the browser in order to track behaviors and display context based-ads from various partners (mostly adware).
MD5:
a511a77493b11057efa6d249e6f51232

SHA-1:
fe95d00353874a671d0387943def7183a17c241e

SHA-256:
c5976de17fa144141b6df09858504fcf4805ef80bd770e89039d710a35f98dcc

Scanner detections:
19 / 68

Status:
Adware

Analysis date:
4/24/2024 1:50:34 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.644630
940

AhnLab V3 Security
Trojan/Win32.HDC
2014.06.10

avast!
Win32:Adware-BNS [PUP]
2014.9-140502

Baidu Antivirus
Adware.Win32.AddLyrics
4.0.3.1452

Bitdefender
Application.Generic.644630
1.0.20.950

Comodo Security
ApplicUnwnt
18496

ESET NOD32
Win32/AdWare.AddLyrics.AK (variant)
8.9747

Fortinet FortiGate
Riskware/AddLyrics
7/9/2014

F-Secure
Application.Generic.644630
11.2014-09-07_4

G Data
Application.Generic.644630
14.7.24

IKARUS anti.virus
AdWare.AddLyrics
t3scan.1.6.1.0

K7 AntiVirus
Adware
13.1712348

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Lyckriks
14.0.0.3585

MicroWorld eScan
Application.Generic.644630
15.0.0.570

NANO AntiVirus
Riskware.Win32.Lyckriks.czgnty
0.28.0.60253

Reason Heuristics
Adware.Revizer.Remarkit.O
14.5.2.5

Sophos
Generic PUA LJ
4.98

Trend Micro House Call
TROJ_GEN.F47V0602
7.2.190

VIPRE Antivirus
Trojan.Win32.Generic
30146

File size:
139.5 KB (142,848 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\re-markit-soft\re-markitxy161.exe

File PE Metadata
Compilation timestamp:
5/1/2014 3:13:10 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
3072:vLEs13yk1KyeDqNrDsQK02ON8Xt2SeJlohJgW:vLEu3rIDqNHsQK0C92ghJ

Entry address:
0xBEA7

Entry point:
E8, BB, 58, 00, 00, E9, 95, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 80, 00, 00, 00, 72, 0E, 83, 3D, 60, 1E, 42, 00, 00, 74, 05, E9, 16, 59, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07...
 
[+]

Code size:
84 KB (86,016 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:14138/

Local host port:
14138

Default credentials:
No


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to ec2-52-7-213-116.compute-1.amazonaws.com  (52.7.213.116:443)

TCP (HTTP):
Connects to ec2-54-149-124-83.us-west-2.compute.amazonaws.com  (54.149.124.83:80)

TCP (HTTP):
Connects to ec2-52-5-232-222.compute-1.amazonaws.com  (52.5.232.222:80)

TCP (HTTP SSL):
Connects to ec2-52-20-120-15.compute-1.amazonaws.com  (52.20.120.15:443)

TCP (HTTP):
Connects to ec2-107-23-224-186.compute-1.amazonaws.com  (107.23.224.186:80)

TCP (HTTP):

TCP (HTTP):
Connects to sjd-rd12-3c.sjc.dropbox.com  (108.160.167.159:80)

TCP (HTTP):
Connects to server-54-230-5-232.dfw3.r.cloudfront.net  (54.230.5.232:80)

TCP (HTTP):
Connects to secondaire.bazoocam.org  (46.105.41.148:80)

TCP (HTTP):
Connects to ec2-54-72-52-58.eu-west-1.compute.amazonaws.com  (54.72.52.58:80)

TCP (HTTP):
Connects to ec2-54-246-181-97.eu-west-1.compute.amazonaws.com  (54.246.181.97:80)

TCP (HTTP):
Connects to ec2-54-171-43-206.eu-west-1.compute.amazonaws.com  (54.171.43.206:80)

TCP (HTTP SSL):
Connects to ec2-52-73-109-231.compute-1.amazonaws.com  (52.73.109.231:443)

TCP (HTTP SSL):
Connects to ec2-52-6-82-78.compute-1.amazonaws.com  (52.6.82.78:443)

TCP (HTTP SSL):
Connects to ec2-34-192-150-200.compute-1.amazonaws.com  (34.192.150.200:443)

Remove re-markitxy161.exe - Powered by Reason Core Security