mupdater.exe

MUpdater

O.T.S.D WEB SERVICES LTD

The application mupdater.exe by O.T.S.D WEB SERVICES has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler named MigrationUpdateTask triggered daily at a specified time.
Publisher:
O.T.S.D WEB SERVICES LTD  (signed and verified)

Product:
MUpdater

Version:
1.3.0.1

MD5:
d584b8ac80d04c5ebc9c21a4fe6186ab

SHA-1:
e51f7c05671451357b15e8df7c018e8c2cfbe52f

SHA-256:
9d41495b8176271e8383389aa7e0c573fe947d766b49cce0225f7d3e99c0d08a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 8:25:14 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OTSDWEBSERVICES (M)
15.9.2.11

File size:
264.8 KB (271,120 bytes)

Product version:
1.3.0.1

Copyright:
Copyright © MUpdater 2012

Original file name:
mupdater.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\migsupdater\mupdater.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/21/2014 1:00:00 AM

Valid to:
8/20/2017 12:59:59 AM

Subject:
CN=O.T.S.D WEB SERVICES LTD, O=O.T.S.D WEB SERVICES LTD, L=Tel aviv -Jaffa, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
15803437D43EF013A5AD5FE5113B15A3

File PE Metadata
Compilation timestamp:
4/8/2015 3:30:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:96eWwCU8jwBDwpnRNSe9+Qx/nfU8FoisaF/DuUxo:dWxkBDwpRNSew2PtxsatDuUxo

Entry address:
0x3BB8E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.1897

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
231 KB (236,544 bytes)

Scheduled Task
Task name:
MigrationUpdateTask

Trigger:
Daily (Runs daily at 12:48)

Description:
Keeps your softwares up to date. If this task is disabled or stopped, your softwares will not be kept up to date, meaning security vulnerabilities tha


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-52-17-58-248.eu-west-1.compute.amazonaws.com  (52.17.58.248:80)

TCP (HTTP):
Connects to ec2-52-17-39-155.eu-west-1.compute.amazonaws.com  (52.17.39.155:80)

Remove mupdater.exe - Powered by Reason Core Security