downloader.exe

MY SECURITY CENTER LTD

The application downloader.exe, “MYSecurityCenter Update Downloader” by MY SECURITY CENTER has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address lithium.mysecuritycenter.com on port 80 using the HTTP protocol.
Publisher:
MYSecurityCenter  (signed by MY SECURITY CENTER LTD)

Product:
MYSecurityCenter

Description:
MYSecurityCenter Update Downloader

Version:
1.0.30.345 95505

MD5:
849026f73772991f49baaea33dbb5171

SHA-1:
de3e9c2f5a6f15e75a6bd0edf030b99c96fcf345

SHA-256:
a50c0b4dc8e800191bac1336a4862b016f4fccf1b875e0ad8a23d379aa79f0b4

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 3:41:20 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.MYSECURITYCENTER
15.1.12.12

File size:
400.3 KB (409,944 bytes)

Product version:
1.0.30.345 95505

Copyright:
@ MYSecurityCenter

Original file name:
downloader.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mysecuritycenter\myinternetsecurity\downloader.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
5/17/2012 1:00:00 AM

Valid to:
7/21/2015 1:00:00 PM

Subject:
CN=MY SECURITY CENTER LTD, O=MY SECURITY CENTER LTD, L=West Drayton, C=GB

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
02B405245A6E01DE7848F7C55FC3BCC7

File PE Metadata
Compilation timestamp:
10/25/2012 3:31:27 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
6144:7/gsyLQQuGCQdUY1Ld9bFnV/U5//98n4G+ZV/+cNXqqadk2UqQy4iacqw:7osCQQvBB1LjdVoH9QctICSTN

Entry address:
0x2E9E8

Entry point:
48, 83, EC, 28, E8, C7, E5, 00, 00, 48, 83, C4, 28, E9, 56, FE, FF, FF, CC, CC, 40, 53, 48, 83, EC, 20, BA, 08, 00, 00, 00, 8D, 4A, 18, E8, 7D, 28, 00, 00, 48, 8B, C8, 48, 8B, D8, E8, CA, 58, 00, 00, 48, 89, 05, EF, 20, 03, 00, 48, 89, 05, E0, 20, 03, 00, 48, 85, DB, 75, 05, 8D, 43, 18, EB, 06, 48, 83, 23, 00, 33, C0, 48, 83, C4, 20, 5B, C3, CC, CC, 48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 48, 89, 7C, 24, 18, 41, 54, 41, 55, 41, 56, 48, 83, EC, 20, 4C, 8B, F1, E8, 13, 63, 00, 00, 90, 48, 8B, 0D, A7, 20, 03...
 
[+]

Entropy:
6.2073

Code size:
290 KB (296,960 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to lithium.mysecuritycenter.com  (188.40.51.149:80)

Remove downloader.exe - Powered by Reason Core Security