mysql-server.exe

UpdateStar GmbH

The application mysql-server.exe by UpdateStar GmbH has been detected as a potentially unwanted program by 14 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.updatestar.com.
Publisher:
UpdateStar GmbH  (signed and verified)

MD5:
996c94b01019f5f96b3e7dd14777cb3d

SHA-1:
cf295b8698e62b1b3d935b314f4086cdc5b219c8

SHA-256:
b93a373ac5351d39461256db55be2a0a35f1122c1b3dde1369d6b782b08b9866

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/28/2024 2:34:50 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
7.11.127.58

Comodo Security
Application.Win32.InstallCore.AX
17677

Dr.Web
Adware.InstallCore.113
9.0.1.044

ESET NOD32
Win32/InstallCore.ES (variant)
8.9339

Malwarebytes
v2014.02.13.01

McAfee
Artemis!40C599D84F09
5600.7220

Qihoo 360 Security
Win32/Virus.Adware.94c
1.0.0.1015

Reason Heuristics
PUP.UpdateStarGmbH.M
14.2.13.13

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14211

Sophos
Install Core Installer
4.97

Trend Micro House Call
TROJ_GEN.F47V0114
7.2.44

Vba32 AntiVirus
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
25820

File size:
663.6 KB (679,552 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/2/2013 12:00:00 AM

Valid to:
1/2/2016 11:59:59 PM

Subject:
CN=UpdateStar GmbH, O=UpdateStar GmbH, STREET=Hauptstraße 20, L=Berlin, S=Berlin, PostalCode=10827, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009ED227324380B40DDE36C8D31A33831F

File PE Metadata
Compilation timestamp:
6/19/1992 10:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:9MJfsG4HfYwcCUI4XMzsoe8+MEGwg9ZzHRpvPOThHP49EYDycyMbegkYZwcZMEZC:9MJfs/Htcw4cAo1BRRHRpPKwpZe8wcZs

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.8449  (probably packed)

Code size:
36 KB (36,864 bytes)

The file mysql-server.exe has been seen being distributed by the following URL.

Remove mysql-server.exe - Powered by Reason Core Security