vosteran.exe

The application vosteran.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘GoogleChromeAutoLaunch’. This file is typically installed with the program Vosteran which is a potentially unwanted software program. While running, it connects to the Internet address isp.ensite-aru1.cache.google.com on port 443.
Version:
31.0.1650.23

MD5:
944a91af08bbed92bd0abc81203042a9

SHA-1:
19b59f86aa75828c863a8cbfafa291e9acc4d5fc

SHA-256:
20b8750fdeec9cd200b2f622d765d997508b1a6b48cdd794b46193b400629f89

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
12/7/2019 1:36:08 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12750616
695

Baidu Antivirus
Hacktool.Win32.ADInstaller
4.0.3.15311

Bitdefender
Trojan.Generic.12750616
1.0.20.350

Emsisoft Anti-Malware
Trojan.Generic.12750616
8.15.03.11.01

F-Secure
Riskware.Application.Browser.FakeBrowser
5.13.68

G Data
Trojan.Generic.12750616
15.3.25

Kaspersky
not-a-virus:RiskTool.Win32.ADInstaller
14.0.0.2362

MicroWorld eScan
Trojan.Generic.12750616
16.0.0.210

Panda Antivirus
Generic Suspicious
15.03.11.01

Qihoo 360 Security
Win32/Virus.RiskTool.a62
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.11.13

VIPRE Antivirus
Threat.4150696
37788

File size:
990.5 KB (1,014,272 bytes)

Product version:
31.0.1650.23

Original file name:
vosteran.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\vosteran\application\vosteran.exe

File PE Metadata
Compilation timestamp:
11/6/2014 11:49:19 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:/CKE094hiiSJ92W9WaJPY7yEYtMOwvmyzppFZE2uXyYz60QT+NMeYtjtlR1FvO0B:6s7y7SMOwvmyFpbCIhTocj/FloWb

Entry address:
0x47242

Entry point:
E8, 58, B2, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, 35, FC, 32, 46, 00, 57, FF, 35, 74, 35, 49, 00, FF, D6, FF, 35, 70, 35, 49, 00, 8B, D8, 89, 5D, FC, FF, D6, 8B, F0, 3B, F3, 0F, 82, 81, 00, 00, 00, 8B, FE, 2B, FB, 8D, 47, 04, 83, F8, 04, 72, 75, 53, E8, AE, B2, 00, 00, 8B, D8, 8D, 47, 04, 59, 3B, D8, 73, 48, B8, 00, 08, 00, 00, 3B, D8, 73, 02, 8B, C3, 03, C3, 3B, C3, 72, 0F, 50, FF, 75, FC, E8, E6, 44, 00, 00, 59, 59, 85, C0, 75, 16, 8D, 43, 10, 3B, C3, 72, 3E, 50, FF, 75, FC, E8...
 
[+]

Code size:
392 KB (401,408 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
GoogleChromeAutoLaunch

Command:
"C:\users\{user}\appdata\local\vosteran\application\vosteran.exe" --auto-launch-at-startup --profile-directory="default"


The file vosteran.exe has been discovered within the following program.

Vosteran  by Vosteran
87% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-165-64-247.compute-1.amazonaws.com  (54.165.64.247:80)

TCP (HTTP):
Connects to m-prd-umpxl-adcom-mtc-b.evip.aol.com  (149.174.28.143:80)

TCP (HTTP):
Connects to ec2-52-206-55-34.compute-1.amazonaws.com  (52.206.55.34:80)

TCP (HTTP):
Connects to ec2-52-86-193-160.compute-1.amazonaws.com  (52.86.193.160:80)

TCP (HTTP):
Connects to server-52-84-26-224.ewr50.r.cloudfront.net  (52.84.26.224:80)

TCP (HTTP):
Connects to s3-1.amazonaws.com  (52.216.224.27:80)

TCP (HTTP):

TCP (HTTP):
Connects to server-52-84-174-164.gru50.r.cloudfront.net  (52.84.174.164:80)

TCP (HTTP SSL):
Connects to s3-1-w.amazonaws.com  (52.216.80.176:443)

TCP (HTTP):
Connects to portalcomunica.kroton.com.br  (187.86.215.135:80)

TCP (HTTP):
Connects to ec2-52-55-57-163.compute-1.amazonaws.com  (52.55.57.163:80)

TCP (HTTP):
Connects to ec2-34-200-157-49.compute-1.amazonaws.com  (34.200.157.49:80)

TCP (HTTP):
Connects to ec2-34-197-167-168.compute-1.amazonaws.com  (34.197.167.168:80)

TCP (HTTP SSL):
Connects to xx-fbcdn-shv-02-gru2.fbcdn.net  (157.240.12.16:443)

TCP (HTTP):
Connects to server-52-84-174-225.gru50.r.cloudfront.net  (52.84.174.225:80)

TCP (HTTP SSL):
Connects to edge-star-shv-01-gru2.facebook.com  (31.13.85.8:443)

TCP (HTTP SSL):
Connects to edge-star-mini-shv-01-gru2.facebook.com  (31.13.85.36:443)

TCP (HTTP):
Connects to ec2-34-198-58-20.compute-1.amazonaws.com  (34.198.58.20:80)

TCP (HTTP):

TCP (HTTP):
Connects to a23-197-50-163.deploy.static.akamaitechnologies.com  (23.197.50.163:80)

Remove vosteran.exe - Powered by Reason Core Security