set.exe

ExtManager

The application set.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Background Logic Handler”. While running, it connects to the Internet address hans-moleman.w3.org on port 80 using the HTTP protocol.
Product:
ExtManager

Version:
1.0.0.0

MD5:
94faa94d5698f119fa53e6e98a5277bf

SHA-1:
77645da620ee5dcf0fdd077be5547475c94e3d42

SHA-256:
8f0e4d908d6508badcba53631c26f64b0e4cf6d094e1dcac3122beda020600d5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 11:40:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Linkury (M)
17.2.14.1

File size:
3.6 MB (3,786,752 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2016

Original file name:
LogicHandler.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\logic handler\set.exe

File PE Metadata
Compilation timestamp:
2/14/2017 7:37:28 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x39DC0E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
3.6 MB (3,784,192 bytes)

Service
Display name:
Background Logic Handler

Service name:
backlh

Type:
Win32OwnProcess


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to hans-moleman.w3.org  (128.30.52.100:80)

Remove set.exe - Powered by Reason Core Security