adobe update.com

The file adobe update.com has been detected as malware by 34 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. While running, it connects to the Internet address box361.bluehost.com on port 80 using the HTTP protocol.
MD5:
4c9b19e2b584317e7a6d1852e4d8c163

SHA-1:
74568f78bdf00a142a7c8c1333b6ae1d9efafe2a

Scanner detections:
34 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/16/2024 8:18:42 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Win32.Sality.BL
7.1.1

AhnLab V3 Security
Win32/Kashu.E
2013.08.29

Avira AntiVirus
W32/Sality.AT
7.11.98.174

avast!
Win32:SaliCode
2014.9-160221

AVG
Worm/VB.10
2017.0.2827

Bitdefender
Worm.SillyShareCopy.E
1.0.20.260

Clam AntiVirus
Worm.VB-117
0.98/18155

Comodo Security
Virus.Win32.Sality.Gen
16841

Dr.Web
Win32.HLLW.Autoruner.874
9.0.1.052

Emsisoft Anti-Malware
Worm.SillyShareCopy
8.16.02.21.08

ESET NOD32
Win32/Sality.NBA
10.8739

F-Prot
W32/Sality.gen2
v6.4.7.1.166

F-Secure
Worm.SillyShareCopy.E
11.2016-21-02_1

G Data
Worm.SillyShareCopy
16.2.22

IKARUS anti.virus
Worm.Win32.AutoRun
t3scan.2.0.127

K7 AntiVirus
Virus
13.170.9419

Kaspersky
Worm.Win32.AutoRun
14.0.0.628

Malwarebytes
Worm.Autorun
v2016.02.21.08

McAfee
W32/Sality.gen.z
5600.6483

Microsoft Security Essentials
Worm:Win32/SillyShareCopy.E
1.163.1557.0

NANO AntiVirus
Virus.Win32.Sality.beygb
0.26.0.54268

Norman
VBWorm.NMX
11.20160221

nProtect
Win32.Sality.3
13.08.28.01

Panda Antivirus
W32/Sality.AA
16.02.21.08

Quick Heal
W32.Sality.U
2.16.12.00

Rising Antivirus
Worm.VB.ajx
23.00.65.16219

Sophos
Mal/Sality-D
4.91

SUPERAntiSpyware
Trojan.Agent/Gen-Autorun[SillyShare]
9310

Total Defense
Win32/Sality.AA
37.0.10498

Trend Micro House Call
PE_SALITY.RL
7.2.52

Trend Micro
PE_SALITY.RL
10.465.21

Vba32 AntiVirus
SScope.Trojan.VBO.0348
3.12.22.3

VIPRE Antivirus
Virus.Win32.Sality.at
20972

ViRobot
Win32.Sality.N
2011.4.7.4223

File size:
108 KB (110,592 bytes)

File PE Metadata
Compilation timestamp:
1/28/2007 9:00:37 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:yFJXgb4ES/bOP5amIP57Cff5k6TWceGN2fLjGDQ/5tFzfTITA1uyILfeOf:aXgO4aZdCff9bwGDQx7zv1ZILfeI

Entry address:
0x110C

Entry point:
87, EE, F7, C7, C5, C7, CF, 71, 02, EE, FE, C4, 69, ED, 1E, C3, 03, 0F, 70, 06, 85, EB, 0F, AF, ED, 47, 45, 80, FE, 86, 89, C8, 14, 61, 2B, F2, 8D, 2D, 40, 84, 88, AB, 89, F3, BF, 2A, C4, 68, 1D, 68, B0, 27, 4D, 00, 68, 76, E9, D3, 00, C6, C5, 7E, 4B, B4, C1, 15, 47, 41, 76, C3, 57, 87, E9, E8, 77, 00, 00, 00, 41, FF, C5, 69, C9, 47, 77, 0A, 09, C7, C0, C4, DF, AF, 34, F7, C0, A1, 0E, EF, FB, 0F, AF, ED, 2B, F6, 1A, F1, 87, D9, 33, F6, 88, C6, 8B, D8, B5, 31, 0F, B6, C9, F3, 85, F3, 2C, 19, B9, 55, 69, 61...
 
[+]

Entropy:
6.9718

Code size:
24 KB (24,576 bytes)

User Start Menu Item
Name:
Adobe Online.com


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to box361.bluehost.com  (69.89.31.161:80)

TCP (HTTP):
Connects to 217-160-0-39.elastic-ssl.ui-r.com  (217.160.0.39:80)

TCP (HTTP):
Connects to 217-160-0-4.elastic-ssl.ui-r.com  (217.160.0.4:80)

TCP (HTTP):
Connects to h30.default-host.net  (138.201.56.16:80)

Remove adobe update.com - Powered by Reason Core Security