wikithemes.exe

Internet Widgits Pty Ltd

The application wikithemes.exe by Internet Widgits Pty has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WikiThemes’. This file is typically installed with the program WikiThemes - WikiThemes for Desktop by WikiThemes. While running, it connects to the Internet address server-54-192-148-243.sin2.r.cloudfront.net on port 443.
Publisher:
Internet Widgits Pty Ltd  (signed and verified)

MD5:
04dd230a05700786a602e65077b3051e

SHA-1:
52c605fd53117736f249029ac9149674238f60c3

SHA-256:
99b6dd8c62c417c0700e8d35ffb2818fbbc74159f0fd6ff4cfcfb2d51b47c271

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/19/2024 11:32:35 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.1.15

File size:
45.7 MB (47,878,576 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\wikithemes\wikithemes.exe

Digital Signature
Authority:
Internet Widgits Pty Ltd

Valid from:
11/14/2016 9:36:30 AM

Valid to:
11/12/2026 9:36:30 AM

Subject:
CN=WikiThemes, O=Internet Widgits Pty Ltd, S=Some-State, C=US

Issuer:
CN=WikiThemes, O=Internet Widgits Pty Ltd, S=Some-State, C=US

Serial number:
00BFAB17CFDB648FE9

File PE Metadata
Compilation timestamp:
2/17/2017 9:17:08 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x1C9A083

Entry point:
E8, 98, 3A, 01, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 8B, 55, 0C, A1, 20, A8, EC, 02, F7, D2, 8B, 4D, 08, 23, D0, 23, 4D, 0C, 0B, D1, 89, 15, 20, A8, EC, 02, 5D, C3, E8, A7, 20, 00, 00, 85, C0, 74, 08, 6A, 16, E8, 6A, 21, 00, 00, 59, F6, 05, 20, A8, EC, 02, 02, 74, 21, 6A, 17, E8, 97, 24, 60, 00, 85, C0, 74, 05, 6A, 07, 59, CD, 29, 6A, 01, 68, 15, 00, 00, 40, 6A, 03, E8, A7, F8, FF, FF, 83, C4, 0C, 6A, 03, E8, 14, FC, FF, FF, CC, 55, 8B, EC, 8D, 45, 18, 50, 6A, 00, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75...
 
[+]

Code size:
34.9 MB (36,637,696 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WikiThemes

Command:
C:\users\{user}\appdata\roaming\wikithemes\wikithemes.exe su


The file wikithemes.exe has been discovered within the following program.

About 9% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to text-lb.ulsfo.wikimedia.org  (198.35.26.96:443)

TCP (HTTP SSL):
Connects to upload-lb.ulsfo.wikimedia.org  (198.35.26.112:443)

TCP (HTTP SSL):
Connects to server-54-192-148-243.sin2.r.cloudfront.net  (54.192.148.243:443)

TCP (HTTP SSL):
Connects to server-54-230-158-169.sin3.r.cloudfront.net  (54.230.158.169:443)

TCP (HTTP SSL):
Connects to mc.yandex.ru  (213.180.193.119:443)

TCP (HTTP):
Connects to ec2-54-225-154-132.compute-1.amazonaws.com  (54.225.154.132:80)

TCP (HTTP):
Connects to ec2-50-17-235-124.compute-1.amazonaws.com  (50.17.235.124:80)

TCP (HTTP):
Connects to ec2-50-16-231-217.compute-1.amazonaws.com  (50.16.231.217:80)

TCP (HTTP):
Connects to ec2-23-23-221-88.compute-1.amazonaws.com  (23.23.221.88:80)

TCP (HTTP):
Connects to c4.3e.559e.ip4.static.sl-reverse.com  (158.85.62.196:80)

TCP (HTTP):
Connects to ec2-23-21-45-51.compute-1.amazonaws.com  (23.21.45.51:80)

TCP (HTTP SSL):
Connects to xx-fbcdn-shv-01-sin6.fbcdn.net  (157.240.7.26:443)

TCP (HTTP):
Connects to ec2-23-23-231-146.compute-1.amazonaws.com  (23.23.231.146:80)

TCP (HTTP SSL):
Connects to a23-2-66-250.deploy.static.akamaitechnologies.com  (23.2.66.250:443)

TCP (HTTP SSL):
Connects to a23-2-27-16.deploy.static.akamaitechnologies.com  (23.2.27.16:443)

TCP (HTTP SSL):
Connects to a23-2-26-191.deploy.static.akamaitechnologies.com  (23.2.26.191:443)

Remove wikithemes.exe - Powered by Reason Core Security