gpupd.exe

Closed Joint-Stock Company

The application gpupd.exe by Closed Joint-Stock Company has been detected as adware by 2 anti-malware scanners. It is also typically executed from the user's temporary directory.
Publisher:
Closed Joint-Stock Company   (signed and verified)

MD5:
c9d38d64f16f22356dd55c881cd8c151

SHA-1:
996cf0530b9bcbb079d3de9d3f72e94ce3a28f81

SHA-256:
8eab6004e0fb2c885c1c030ee55783c99bf607892ea4b11bcdfafd190007cc1f

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
4/20/2024 8:00:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ClosedJointStockCompany.F
14.5.30.12

VIPRE Antivirus
GetPrivate
29752

File size:
815 KB (834,584 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\gpupd.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/11/2013 1:00:00 AM

Valid to:
9/11/2016 12:59:59 AM

Subject:
CN="Closed Joint-Stock Company ""V.X. Technocom", O="Closed Joint-Stock Company ""V.X. Technocom", STREET="Staromonetnyi per. 14, bld. 2", L=Moscow, S=Moscow, PostalCode=119180, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
422C9081573539C78689D8F203970268

File PE Metadata
Compilation timestamp:
5/20/2014 7:42:24 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:RpkOviojNjohbQKzMPGOkr8NZtgdIcCuuevE888888888888W88888888888f:riojNjWbQKIPG0gd9v0

Entry address:
0xAAE7C

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, 57, B8, C8, 51, 4A, 00, E8, 35, EF, F5, FF, 33, C0, 55, 68, 30, AF, 4A, 00, 64, FF, 30, 64, 89, 20, B8, 5B, 8F, 02, 00, E8, 01, A3, FF, FF, B8, 64, AF, 4A, 00, E8, BB, 9F, FF, FF, B8, 78, AF, 4A, 00, E8, E5, 9D, FF, FF, 84, C0, 75, 49, BA, B4, AF, 4A, 00, B8, DC, AF, 4A, 00, E8, DA, 9E, FF, FF, 6A, 00, 6A, 00, 68, 50, B0, 4A, 00, 68, 08, B1, 4A, 00, 68, 24, B1, 4A, 00, 6A, 00, E8, 34, 9B, FF, FF, B8, 3C, B1, 4A, 00, E8, 7A, 9F, FF, FF, B9, 50, B1, 4A, 00, BA, 60, B1, 4A, 00...
 
[+]

Entropy:
6.3665

Developed / compiled with:
Microsoft Visual C++

Code size:
677 KB (693,248 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to a23-53-115-152.deploy.static.akamaitechnologies.com  (23.53.115.152:80)

Remove gpupd.exe - Powered by Reason Core Security