Gemplus Cryptographic Service Provider

T

tekctrl1949

Guest
While reviewing my firewall logs, I noted that something called Gemplus Cryptographic Service Provider recently started hammering at my firewall, trying to access a LOT of different IP addresses, all using TCP/IP destination ports 53, 443 and 5050. The origination ports are all over the map but don't seem to appear more than once. This GCSP appears to be something related to secure card readers, which I haven't loaded and don't use. Does anyone have any info on A) what this is, B) where it might have originated, C) and what it's trying to accomplish? My intuition tells me that it's malware, yet all of my malware scans come up empty. I'm really curious about this thing. My system says "no such file" when I go looking for "oiu0.1496646520172633.exe", and a Tracert to 216.244.77.251 results in;

1 1 ms <1 ms 1 ms home [192.168.1.254]
2 47 ms 47 ms 49 ms adsl-75-0-47-254.dsl.covlil.sbcglobal.net [75.0.
47.254]
3 47 ms 51 ms 51 ms dist1-vlan50.covlil.ameritech.net [66.72.43.226]
4 50 ms 45 ms 48 ms 12.83.48.122
5 58 ms 57 ms 55 ms cgcil03jt.ip.att.net [12.122.84.53]
6 55 ms 56 ms 53 ms chp-brdr-03.inet.qwest.net [63.146.26.217]
7 Request timed out.
8 113 ms 110 ms 67.129.97.131
9 67.129.97.131 reports: Destination host unreachable.
Trace complete.

A Very Small sample of the firewall log follows, for your edification:

PE,2012/01/13,12:04:00 -6:00 GMT,Gemplus Cryptographic Service Provider,C:\Documents and Settings\Jack\Local Settings\Temp\oiu0.1496646520172633.exe,216.244.77.251:80,N/A,http://pralerts.zonealarm.com/pralerts/pranalyze.jsp?PN=&VER=&FN=&Size=0&MD5=35000000ecde6101ee55aa61e0a74702&SKIMP=35000000ecde6101ee55aa61e0a74702&&RIPA=&RP=20480&Connect=1&Pgmstatus=1&Zone=2&Keycode=j5hvqhisiu3s4he7bhx644bu4g0&Product=ZoneAlarm&ProductVersion=10.1.065.000&HU100=ZLN22176457661065-1001&CL=en&OEM=1025&SKU=0&Mode=6&QSRC=1&PU=1&OS=Windows+XP-5.1.2600-Service+Pack+3-SMP&LANG=1033
PE,2012/01/13,12:04:00 -6:00 GMT,Gemplus Cryptographic Service Provider,C:\Documents and Settings\Jack\Local Settings\Temp\oiu0.1496646520172633.exe,216.244.77.251:80,N/A,http://pralerts.zonealarm.com/pralerts/pranalyze.jsp?PN=Gemplus+Cryptographic+Service+Provider&VER=5.1.2522.0&FN=oiu0.1496646520172633.exe&Created=402d607c&Size=304128&MD5=c4bfb8e36004032ad9d3edd5c2f77d7b&SKIMP=09ea4ea6742cec465ef167c749051484&&RIPA=&RP=20480&Connect=1&Pgmstatus=1&Zone=2&Keycode=j5hvqhisiu3s4he7bhx644bu4g0&Product=ZoneAlarm&ProductVersion=10.1.065.000&HU100=ZLN22176457661065-1001&CL=en&OEM=1025&SKU=0&Mode=6&QSRC=1&PU=1&OS=Windows+XP-5.1.2600-Service+Pack+3-SMP&LANG=1033
ACCESS,2012/01/13,12:04:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (216.244.77.251:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:04:30 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (216.244.77.250:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:06:34 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (69.64.43.176:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:07:00 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (173.208.214.186:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:07:00 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (85.17.87.9:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:07:00 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (50.7.241.250:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:07:00 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (192.168.1.254:DNS).,N/A,N/A
ACCESS,2012/01/13,12:07:00 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (207.46.232.182:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:07:00 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (207.46.197.32:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:07:02 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (85.17.87.38:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:07:02 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (50.7.241.251:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:07:02 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (96.9.130.117:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:07:02 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (173.208.214.187:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:07:02 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (207.46.197.32:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:07:02 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (176.56.229.123:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:07:02 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (207.46.232.182:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:17:18 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (192.168.1.254:DNS).,N/A,N/A
ACCESS,2012/01/13,12:17:18 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (50.7.241.251:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:17:18 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (85.17.87.38:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:17:18 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (173.208.214.186:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:17:18 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (96.9.130.118:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:17:20 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (93.113.37.251:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:17:20 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (50.7.240.243:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:17:20 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (173.208.229.163:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:17:20 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (176.56.229.124:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:17:20 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (192.168.1.254:DNS).,N/A,N/A
ACCESS,2012/01/13,12:17:34 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (207.46.197.32:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:17:34 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (207.46.232.182:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:17:36 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (192.168.1.254:DNS).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (50.7.241.251:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (173.208.214.186:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (50.7.241.250:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (85.17.87.9:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (96.9.130.117:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (176.56.229.123:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (50.7.240.243:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (192.168.1.254:DNS).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (94.75.208.154:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (199.168.189.25:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (207.46.197.32:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (207.46.232.182:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (192.168.1.254:DNS).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (192.168.1.254:DNS).,N/A,N/A
ACCESS,2012/01/13,12:27:54 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (85.17.193.11:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:56 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (173.208.228.187:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:56 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (50.7.240.243:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:27:56 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (93.113.37.250:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:28:08 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (192.168.1.254:DNS).,N/A,N/A
ACCESS,2012/01/13,12:28:08 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (207.46.232.182:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (192.168.1.254:DNS).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (50.7.241.251:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (50.7.241.250:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (85.17.87.38:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (96.9.130.118:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (85.17.87.9:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (93.113.37.251:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (93.113.37.250:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (94.75.208.154:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (50.7.240.243:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (199.168.189.25:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (176.56.229.123:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (192.168.1.254:DNS).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (173.208.214.187:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:28 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (96.9.130.117:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:30 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (176.56.229.124:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:30 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (173.208.229.163:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:30 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (192.168.1.254:DNS).,N/A,N/A
ACCESS,2012/01/13,12:38:30 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (50.7.240.242:HTTP).,N/A,N/A
ACCESS,2012/01/13,12:38:46 -6:00 GMT,Gemplus Cryptographic Service Provider was blocked from connecting to the Internet (207.46.232.182:HTTP).,N/A,N/A

Continue reading...
 
Back
Top