StormAlertsApp.exe

StormAlertsApp

Weather Warnings LLC

Part of an adware web browser extension that delivers advertisements such as coupons, price-comparisons, display media, affiliate links, banners, popups/popunders and other links. The application StormAlertsApp.exe by Weather Warnings has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program StormAlerts by Weather Warnings LLC which is a potentially unwanted software program.
Publisher:
Weather Warnings LLC  (signed and verified)

Product:
StormAlertsApp

Version:
1.0.14.0

MD5:
db5e2b530baf2f0fc2b6f5af2324c0d0

SHA-1:
764485c1db5052226ef61fa190d84b7ee0d49ed4

SHA-256:
e13db22480815ac460b96c052432de77ae84e56611aa19caab382e4d76a1d323

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
8/22/2018 6:40:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WeatherWarnings.O
14.8.8.1

File size:
598.1 KB (612,464 bytes)

Product version:
1.0.14.0

Original file name:
StormAlertsApp.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\stormalerts\stormalertsapp.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/15/2013 8:00:00 PM

Valid to:
10/16/2014 7:59:59 PM

Subject:
CN=Weather Warnings LLC, O=Weather Warnings LLC, STREET="250 Park Ave #504", L=Minneapolis, S=MN, PostalCode=55415, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E8DB5153F5DF039D40C9CA815EC69821

File PE Metadata
Compilation timestamp:
2/25/2014 4:47:24 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:RPf/B4rkuc48JHh+lrydwsux6UKo7vNf6XcS6AJybBJ:RPf/a84shoEkx6ENf6XctAc

Entry address:
0x7B011

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.0329

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
484.5 KB (496,128 bytes)

The file StormAlertsApp.exe has been discovered within the following program.

StormAlerts  by Weather Warnings LLC
StormAlerts is an ad-supported free web browser extension. The program will also randomly popup various advertisements in a window when the user uses their PC regardless if they are using the web browser or not.
www.storm-alerts.net
86% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-244-235-164.us-west-2.compute.amazonaws.com  (54.244.235.164:80)

TCP (HTTP):
Connects to ec2-54-245-252-128.us-west-2.compute.amazonaws.com  (54.245.252.128:80)

TCP (HTTP):
Connects to ec2-54-244-249-173.us-west-2.compute.amazonaws.com  (54.244.249.173:80)

TCP (HTTP):
Connects to ec2-54-244-226-131.us-west-2.compute.amazonaws.com  (54.244.226.131:80)

TCP (HTTP):
Connects to ec2-54-244-117-30.us-west-2.compute.amazonaws.com  (54.244.117.30:80)

TCP (HTTP):
Connects to server-54-230-90-33.ind6.r.cloudfront.net  (54.230.90.33:80)

TCP (HTTP):
Connects to server-54-230-5-21.dfw3.r.cloudfront.net  (54.230.5.21:80)

TCP (HTTP):
Connects to server-54-230-39-73.jfk1.r.cloudfront.net  (54.230.39.73:80)

TCP (HTTP):
Connects to server-54-230-39-63.jfk1.r.cloudfront.net  (54.230.39.63:80)

TCP (HTTP):
Connects to server-54-230-38-72.jfk1.r.cloudfront.net  (54.230.38.72:80)

TCP (HTTP):
Connects to server-54-230-38-158.jfk1.r.cloudfront.net  (54.230.38.158:80)

TCP (HTTP):
Connects to server-54-230-38-115.jfk1.r.cloudfront.net  (54.230.38.115:80)

TCP (HTTP):
Connects to server-54-230-134-57.syd1.r.cloudfront.net  (54.230.134.57:80)

TCP (HTTP):
Connects to server-54-192-3-140.lhr5.r.cloudfront.net  (54.192.3.140:80)

TCP (HTTP):
Connects to server-52-84-7-142.ord54.r.cloudfront.net  (52.84.7.142:80)

TCP (HTTP):
Connects to ec2-54-245-90-168.us-west-2.compute.amazonaws.com  (54.245.90.168:80)

TCP (HTTP):
Connects to ec2-54-245-246-1.us-west-2.compute.amazonaws.com  (54.245.246.1:80)

TCP (HTTP):
Connects to ec2-54-245-226-206.us-west-2.compute.amazonaws.com  (54.245.226.206:80)

TCP (HTTP):
Connects to ec2-54-244-95-248.us-west-2.compute.amazonaws.com  (54.244.95.248:80)

TCP (HTTP):
Connects to ec2-54-244-118-143.us-west-2.compute.amazonaws.com  (54.244.118.143:80)

Remove StormAlertsApp.exe - Powered by Reason Core Security