fbdownloaderupdate.exe

HTTO GROUP Ltd

The application fbdownloaderupdate.exe by HTTO GROUP has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “FBDownloader Update Service”.
Publisher:
HTTO GROUP Ltd  (signed and verified)

MD5:
e81399b3182cb889a88167a512196065

SHA-1:
65b14c5728be945e710156f7b0c08f2e2fb28008

SHA-256:
a1e9b5a4321a1b68d7ab4fa667427e968656e15c1657108803f650b646512df2

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
7/6/2025 12:37:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.9.7.15

File size:
22.1 KB (22,640 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\fbdownloader\fbdownloaderupdate.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/7/2012 6:34:46 AM

Valid to:
6/8/2013 6:34:46 AM

Subject:
CN=HTTO GROUP Ltd, O=HTTO GROUP Ltd, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11215406F83784DB7388225378818F7FF3A2

File PE Metadata
Compilation timestamp:
7/22/2012 3:01:33 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
384:eKcKuEqdr83vKcRizhsZsoIIARSIFvv2v92SFitqXODro9cEIY7MuIT1D47I9KP4:eKtyax6hEIY7Mlxck96R9KY5k

Entry address:
0x3540

Entry point:
48, 83, EC, 58, FF, 15, 26, 0B, 00, 00, 48, 8D, 54, 24, 20, 48, 8B, C8, FF, 15, 18, 0C, 00, 00, 48, 89, 44, 24, 28, 48, 83, 7C, 24, 28, 00, 0F, 84, AC, 00, 00, 00, 83, 7C, 24, 20, 01, 0F, 8E, 96, 00, 00, 00, 48, 8B, 44, 24, 28, 48, 8B, 48, 08, FF, 15, 65, 0B, 00, 00, FF, C0, 48, 98, 48, D1, E0, 48, 8B, D0, B9, 40, 00, 00, 00, FF, 15, 70, 0B, 00, 00, 48, 89, 05, B9, 2A, 00, 00, 48, 83, 3D, B1, 2A, 00, 00, 00, 74, 61, 48, 8B, 44, 24, 28, 48, 8B, 50, 08, 48, 8B, 0D, 9F, 2A, 00, 00, FF, 15, 99, 0B, 00, 00, E8...
 
[+]

Entropy:
5.6024

Code size:
10 KB (10,240 bytes)

Service
Display name:
FBDownloader Update Service

Service name:
FBDownloaderUpdate

Type:
Win32OwnProcess


Remove fbdownloaderupdate.exe - Powered by Reason Core Security