synclib.engine.exe

Bandoo Media Inc

The application synclib.engine.exe, “EngineRunner rev.229” by Bandoo Media Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “SyncLibEngine”. While running, it connects to the Internet address ip-50-63-202-62.ip.secureserver.net on port 80 using the HTTP protocol.
Publisher:
SyncLib  (signed by Bandoo Media Inc)

Product:
SyncLib

Description:
EngineRunner rev.229

Version:
1.5.0.0

MD5:
e11eb973cc14539e7077318e4a1b5ea2

SHA-1:
4308af35cb936713bd3194d98b64af4993ee265d

SHA-256:
432c890ade9c5cd278bf5d2611f0a140e30d2059020255a546d55c03db2cd988

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 3:32:27 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Service.BandooMedia.N
14.2.21.1

File size:
29.4 KB (30,096 bytes)

Product version:
1.5.0.0

Copyright:
Copyright © 2012 Bandoo Media Inc. All Rights Reserved.

Trademarks:
SyncLib

Original file name:
SyncLib.EngineRunner.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\synclib\synclib.engine.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
10/6/2010 2:00:00 AM

Valid to:
10/6/2012 1:59:59 AM

Subject:
CN=Bandoo Media Inc, O=Bandoo Media Inc, L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5915CD3A113B9B2AE7B497DDDFCDF8F5

File PE Metadata
Compilation timestamp:
4/22/2012 12:36:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:aKS0K+Wgtpi7eObiW3MgRNM3UxXIZUwnMLl:3dziyObncgrM3UxIZUwnMR

Entry address:
0x6FDE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, 38, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 50, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 68, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
20 KB (20,480 bytes)

Service
Display name:
SyncLibEngine

Type:
Win32OwnProcess


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ip-50-63-202-62.ip.secureserver.net  (50.63.202.62:80)

Remove synclib.engine.exe - Powered by Reason Core Security