sacdgqexrr.exe

Weather Alert

Fast Lane Development

The application sacdgqexrr.exe, “WeatherAlert Service” by Fast Lane Development has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “sACDGqExRr”.
Publisher:
Fast Lane Development  (signed and verified)

Product:
Weather Alert

Description:
WeatherAlert Service

Version:
1.0.0.0

MD5:
7c47618939d2c66164fd68b5e02b9b70

SHA-1:
4b8d09b8cc59449b4a76319af630805a50e21c96

SHA-256:
4adc70481a875caff5bc08e7a96ec60bb144fc19bad98c7be14e8901474be83c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
6/24/2025 9:36:12 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt.FastLaneDevelopment (M)
16.3.8.17

File size:
2.9 MB (3,000,000 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Fast Lane Development 2016

Original file name:
WeatherAlertService.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\tnlwaxoqbk\sacdgqexrr.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/3/2015 1:36:21 PM

Valid to:
11/3/2016 1:36:21 PM

Subject:
CN=Fast Lane Development, O=Fast Lane Development, L=Warrens, S=Saint Michael, C=BB

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11211B8F1051797C18F993CD4F0D6C793447

File PE Metadata
Compilation timestamp:
3/8/2016 1:42:42 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:RbTEbxwCHsOFZjtehjIG0DlkGucmuCUcLIeTXN7gD8jjjlC/ey+/fno:hW5kZIfDl3tCUcLvd7gclCG1/fo

Entry address:
0x2DC50E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.9 MB (2,991,616 bytes)

Service
Display name:
sACDGqExRr

Type:
Win32OwnProcess

Depends on:
Winmgmt CryptSvc


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-52-16-174-255.eu-west-1.compute.amazonaws.com  (52.16.174.255:80)

TCP (HTTP):
Connects to ec2-54-171-43-206.eu-west-1.compute.amazonaws.com  (54.171.43.206:80)

TCP (HTTP):
Connects to ec2-54-171-226-204.eu-west-1.compute.amazonaws.com  (54.171.226.204:80)

TCP (HTTP):
Connects to ec2-54-246-181-97.eu-west-1.compute.amazonaws.com  (54.246.181.97:80)

TCP (HTTP):
Connects to ec2-54-76-91-10.eu-west-1.compute.amazonaws.com  (54.76.91.10:80)

TCP (HTTP):
Connects to ec2-34-250-194-62.eu-west-1.compute.amazonaws.com  (34.250.194.62:80)

TCP (HTTP):
Connects to ec2-52-16-46-192.eu-west-1.compute.amazonaws.com  (52.16.46.192:80)

TCP (HTTP):
Connects to server-54-192-14-177.ams1.r.cloudfront.net  (54.192.14.177:80)

TCP (HTTP):
Connects to ec2-52-19-122-150.eu-west-1.compute.amazonaws.com  (52.19.122.150:80)

Remove sacdgqexrr.exe - Powered by Reason Core Security