SpeedMaxPc.exe

MaxTuneUp, llc

The application SpeedMaxPc.exe by MaxTuneUp, llc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler.
Publisher:
SpeedMaxPc  (signed by MaxTuneUp, llc)

Product:
SpeedMaxPc

Version:
3.3.22.0

MD5:
bb1fd4f7422969e0d7b87c8ef2929855

SHA-1:
b53a4e1082240e2c5dc22ae82119683e3de4d2b9

SHA-256:
a87d48ccc3e47908db1da9efce6cc7b28733a1a7d3eaf6313b6ccecc1e5f4d39

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/16/2024 6:06:39 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SpeedMaxPC (L)
17.1.17.10

File size:
5.6 MB (5,864,384 bytes)

Product version:
3.3.22.0

Copyright:
Copyright © 2017 SpeedMaxPc

Original file name:
SpeedMaxPc.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\speedmaxpc\speedmaxpc\speedmaxpc.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
4/1/2016 1:00:00 AM

Valid to:
4/2/2018 12:59:59 AM

Subject:
CN="MaxTuneUp, llc", O="MaxTuneUp, llc", L=Bangor, S=Maine, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
51D1F61C58CD911D06E921F427D33AA6

File PE Metadata
Compilation timestamp:
1/13/2017 6:22:40 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x359E15

Entry point:
E8, 01, 60, 01, 00, E9, 7F, FE, FF, FF, 3B, 0D, C0, 35, 91, 00, 75, 02, F3, C3, E9, 0A, 29, 00, 00, 55, 8B, EC, 56, 8B, 75, 14, 85, F6, 75, 04, 33, C0, EB, 6D, 8B, 45, 08, 85, C0, 75, 13, E8, 5D, 6F, 00, 00, 6A, 16, 5E, 89, 30, E8, 1B, 05, 01, 00, 8B, C6, EB, 53, 57, 8B, 7D, 10, 85, FF, 74, 14, 39, 75, 0C, 72, 0F, 56, 57, 50, E8, F4, 81, 00, 00, 83, C4, 0C, 33, C0, EB, 36, FF, 75, 0C, 6A, 00, 50, E8, 32, 88, 00, 00, 83, C4, 0C, 85, FF, 75, 09, E8, 1C, 6F, 00, 00, 6A, 16, EB, 0C, 39, 75, 0C, 73, 13, E8, 0E...
 
[+]

Entropy:
6.6306

Code size:
4.1 MB (4,290,048 bytes)

Scheduled Task
Task name:
SpeedMaxPc Update

Trigger:
Weekly (Runs weekly on Sundays at 01:47)

Description:
SpeedMaxPc Update scheduled task.


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-52-73-217-72.compute-1.amazonaws.com  (52.73.217.72:80)

TCP (HTTP):
Connects to server-52-84-33-202.ewr50.r.cloudfront.net  (52.84.33.202:80)

TCP (HTTP):
Connects to h66-38-130-217.gtcust.grouptelecom.net  (66.38.130.217:80)

TCP (HTTP):
Connects to ec2-54-152-186-3.compute-1.amazonaws.com  (54.152.186.3:80)

TCP (HTTP):
Connects to ec2-52-54-139-246.compute-1.amazonaws.com  (52.54.139.246:80)

TCP (HTTP SSL):
Connects to ec2-52-22-119-8.compute-1.amazonaws.com  (52.22.119.8:443)

Remove SpeedMaxPc.exe - Powered by Reason Core Security