Trezaa.Scheduler.exe

Trezaa.Scheduler

trezaa.com

The application Trezaa.Scheduler.exe by trezaa.com has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. While running, it connects to the Internet address 54.32.199.65.philadelphia.google-ggc.verizon.com on port 80 using the HTTP protocol.
Publisher:
Microsoft  (signed by trezaa.com)

Product:
Trezaa.Scheduler

Version:
1.0.0.0

MD5:
9975816902e13536665d7af68c979fbc

SHA-1:
f6f483faa05340ec943026dc73d6266f505c364e

SHA-256:
367131e0d2b37d2b8f9de05543c3a9e13cc82e55fc92c905febea0ef3b9d4e96

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/20/2018 9:13:22 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Trezaa (L)
16.10.10.8

File size:
24.4 KB (25,000 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Microsoft 2015

Original file name:
Trezaa.Scheduler.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\trezaa\trezaa.scheduler.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
5/16/2016 8:00:00 PM

Valid to:
6/5/2018 7:59:59 PM

Subject:
CN=trezaa.com, O=trezaa.com, L=San Leandro, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
604C0C561BA32858CAE76F0D7D1E6E7D

File PE Metadata
Compilation timestamp:
5/20/2016 1:14:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:w+xtpJUf/5Cq7VYzR9YwmaV9vF+1TIYpO6TWlxvWwvnYPLtDzj:wYtpyf/5CWcZV9uxKxrv0Xj

Entry address:
0x5F2E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.1116

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16 KB (16,384 bytes)

Scheduled Task
Task name:
Trezaa Scheduler

Trigger:
Daily (Runs daily at 5:00 PM)

Description:
This App monitors the health of the Windows Service


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to 20.32.199.65.philadelphia.google-ggc.verizon.com  (65.199.32.20:80)

TCP (HTTP):
Connects to host56.promnetwork.com  (65.246.5.56:80)

TCP (HTTP):
Connects to 88.32.199.65.philadelphia.google-ggc.verizon.com  (65.199.32.88:80)

TCP (HTTP):
Connects to 59.32.199.65.philadelphia.google-ggc.verizon.com  (65.199.32.59:80)

TCP (HTTP):
Connects to 58.32.199.65.philadelphia.google-ggc.verizon.com  (65.199.32.58:80)

TCP (HTTP):
Connects to 54.32.199.65.philadelphia.google-ggc.verizon.com  (65.199.32.54:80)

TCP (HTTP):
Connects to 21.32.199.65.philadelphia.google-ggc.verizon.com  (65.199.32.21:80)

TCP (HTTP):
Connects to 184.32.199.65.philadelphia.google-ggc.verizon.com  (65.199.32.184:80)

TCP (HTTP):
Connects to 153.32.199.65.philadelphia.google-ggc.verizon.com  (65.199.32.153:80)

Remove Trezaa.Scheduler.exe - Powered by Reason Core Security