TornTVApp.exe

Cool Mirage ltd.

This is part of a CoolMirage installatation, a potentially unwanted program (PUP) that display ads on the computer. The application TornTVApp.exe by Cool Mirage ltd has been detected as adware by 6 anti-malware scanners. This is a setup program which is used to install the application. The setup installer will bundle multiple adware offers during download and setup (based on the user's geographical location) including toolbars, extensions and coupon utilities. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from cmp.sporttvapp.com and multiple other hosts. While running, it connects to the Internet address sage.parklogic.com on port 80 using the HTTP protocol.
Publisher:
TornTVApp  (signed by Cool Mirage ltd.)

Product:
TornTVApp

Version:
2.0.0.1

MD5:
4a7710b86c7eb48dca4f317b02ded9d9

SHA-1:
895b0e9b6173ea964f583b7dfc2e5d92f1de1625

SHA-256:
56dc317586f67366133d814defc2387da55fe99ed72fce30552585ef2f1bc371

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Bundles a number of adware programs in the installer.

Analysis date:
5/21/2024 7:35:20 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Torn
2014.01.10

avast!
Win32:PUP-gen [PUP]
2014.9-131225

Dr.Web
Adware.Downware.625
9.0.1.0359

MicroWorld eScan
Win32:PUP-gen [PUP]
14.0.0.1077

Reason Heuristics
PUP.CoolMirageltd.J
14.8.7.18

VIPRE Antivirus
CoolMirage Ltd
25260

File size:
812.1 KB (831,600 bytes)

Product version:
2.0.0.1

Copyright:
(c) TornTVApp.com All rights reserved.

Original file name:
TornTVApp.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\torntvapp.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/14/2012 12:00:00 AM

Valid to:
11/14/2014 11:59:59 PM

Subject:
CN=Cool Mirage ltd., O=Cool Mirage ltd., STREET=ogarit 39, L=tel aviv, S=tel aviv, PostalCode=69016, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FC28659CC8073606EF4D09A1994B1AD0

File PE Metadata
Compilation timestamp:
10/31/2012 12:03:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:sMpo37S8PkUWLcInDGT/r2Ux2eiGbsoo5xwadNlAZf+uAiK3CfIoI:sJkjGTDZMeiGbspRd0ZGDt

Entry address:
0x21375

Entry point:
E8, 62, 74, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 58, 59, 87, 04, 24, FF, E0, 58, 59, 87, 04, 24, FF, E0, 8B, FF, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, F1, 13, 42, 00, 6A, 00, FF, 75, 0C, FF, 75, F8, FF, 75, 08, E8, EF, 06, 01, 00, 8B, 45, 0C, 8B...
 
[+]

Code size:
203.5 KB (208,384 bytes)

The file TornTVApp.exe has been seen being distributed by the following 8 URLs.

http://cmp.sporttvapp.com/TornTVApp.exe

http://cmp.install-sources.com/TornTVApp.exe

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to sage.parklogic.com  (69.39.236.56:80)

Remove TornTVApp.exe - Powered by Reason Core Security