shopwit.exe

PayByAds ltd.

The application shopwit.exe by PayByAds ltd has been detected as adware by 28 anti-malware scanners. This file is typically installed with the program Shop-wit by shopwit which is a potentially unwanted software program. While running, it connects to the Internet address unknown.prolexic.com on port 80 using the HTTP protocol.
Publisher:
Pay By Ads LTD  (signed by PayByAds ltd.)

Version:
1.3.0.0

MD5:
47ce240dd9112188080187e7c038b69b

SHA-1:
0c4c28616261018580a4f43ab124a184bae7d50a

Scanner detections:
28 / 68

Status:
Adware

Analysis date:
5/9/2024 7:22:02 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.PayByAds.A
750

Avira AntiVirus
ADWARE/Adware.Gen7
7.11.200.132

AVG
Paybyads
2015.0.3329

Baidu Antivirus
Hacktool.Win32.Montiera
4.0.3.15116

Bitdefender
Adware.PayByAds.A
1.0.20.80

Bkav FE
W32.HfsAdware
1.3.0.6267

Emsisoft Anti-Malware
Adware.PayByAds
8.15.01.16.01

ESET NOD32
Win32/Toolbar.Montiera (variant)
8.10490

Fortinet FortiGate
Riskware/Montiera
10/6/2014

F-Secure
Adware.PayByAds.A
11.2015-16-01_6

G Data
Adware.PayByAds
15.1.24

IKARUS anti.virus
not-a-virus:Downloader.Montiera
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.191.14617

Kaspersky
not-a-virus:Downloader.Win32.Montiera
14.0.0.3141

Malwarebytes
PUP.Optional.PayByAds.A
v2014.10.06.09

McAfee
Artemis!47CE240DD911
5600.6985

MicroWorld eScan
Adware.PayByAds.A
16.0.0.48

nProtect
Adware.PayByAds.A
15.01.12.01

Panda Antivirus
Trj/Chgt.I
14.10.06.09

Qihoo 360 Security
Win32/Virus.Downloader.42e
1.0.0.1015

Quick Heal
Downloader.Montiera.r5 (Not a Virus)
1.15.14.00

Reason Heuristics
PUP.Montiera.PayByAdsltd
15.1.16.1

Sophos
PayByAds
4.98

Trend Micro House Call
TROJ_SPNR.25JS14
7.2.16

Trend Micro
TROJ_SPNR.25JS14
10.465.16

Vba32 AntiVirus
Downloader.Montiera
3.12.26.3

VIPRE Antivirus
Montiera
33562

ViRobot
Adware.Agent.528744[h]
2014.3.20.0

File size:
516.4 KB (528,744 bytes)

Copyright:
All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Application data\shopwit\shopwit\1.3.14.1\shopwit.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/28/2014 10:00:00 AM

Valid to:
7/29/2015 9:59:59 AM

Subject:
CN=PayByAds ltd., O=PayByAds ltd., STREET="Herbert Samuel, 46", L=Tel Aviv, S=Israel, PostalCode=6330303, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CA9E6FD9AC89FBB9BC192CA9530A98F5

File PE Metadata
Compilation timestamp:
9/29/2014 1:37:48 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:HOF0c1xOzpdDtJ9JmHJgAVMVij7FZBRMrtZ:lSiVij7FZortZ

Entry address:
0x41509

Entry point:
E8, 3B, 84, 00, 00, E9, 89, FE, FF, FF, B8, 8E, A4, 44, 00, A3, D0, 39, 47, 00, C7, 05, D4, 39, 47, 00, 84, 9B, 44, 00, C7, 05, D8, 39, 47, 00, 38, 9B, 44, 00, C7, 05, DC, 39, 47, 00, 71, 9B, 44, 00, C7, 05, E0, 39, 47, 00, DA, 9A, 44, 00, A3, E4, 39, 47, 00, C7, 05, E8, 39, 47, 00, 06, A4, 44, 00, C7, 05, EC, 39, 47, 00, F6, 9A, 44, 00, C7, 05, F0, 39, 47, 00, 58, 9A, 44, 00, C7, 05, F4, 39, 47, 00, E4, 99, 44, 00, C3, 8B, FF, 55, 8B, EC, E8, 96, FF, FF, FF, 83, 7D, 08, 00, 74, 05, E8, 29, 8F, 00, 00, DB...
 
[+]

Entropy:
6.2803

Code size:
359.5 KB (368,128 bytes)

The file shopwit.exe has been discovered within the following program.

Shop-wit  by shopwit
Shopwit is an adware browser extension that will display banner and text-context link ads aimed to promote the installation of additional questionable content including web browser toolbars, optimization utilities and other products.
79% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-72-9-115.eu-west-1.compute.amazonaws.com  (54.72.9.115:80)

TCP (HTTP):
Connects to sage.parklogic.com  (69.39.236.56:80)

TCP (HTTP):
Connects to unknown.prolexic.com  (72.52.4.90:80)

Remove shopwit.exe - Powered by Reason Core Security