OutfoxTvUpdater.exe

Outfox Tv Updater

Outfox Tv Productions Pty Ltd

The application OutfoxTvUpdater.exe by Outfox Tv Productions Pty has been detected as a potentially unwanted program by 6 anti-malware scanners. It runs as a windows Service named “OutfoxTvUpdater”. While running, it connects to the Internet address li963-234.members.linode.com on port 80 using the HTTP protocol.
Publisher:
Outfox Tv Productions Pty Ltd  (signed and verified)

Product:
Outfox Tv Updater

Description:
OutfoxTvUpdater

Version:
1.1.3.0

MD5:
bd0e79837177e9d7ae9130b7643f1c67

SHA-1:
80547784f13f2473070521f2068e68c2def660c8

SHA-256:
52d9eb1ed623899d8ef9697e17cab658912dea3461f0cf9ac628d85d89692f95

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
4/23/2024 1:54:10 PM UTC  (today)

Scan engine
Detection
Engine version

McAfee
Artemis!B163B3585AFA
5600.7028

Reason Heuristics
PUP.OutfoxTvProductionsPty.P
14.8.25.7

Sophos
OutFox TV
4.98

Trend Micro House Call
Suspicious_GEN.F47V0729
7.2.237

File size:
191.9 KB (196,496 bytes)

Product version:
1.1.3.0

Copyright:
Copyright (C) 2014

Original file name:
OutfoxTvUpdater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\outfoxtv\outfoxtvupdater.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/2/2013 4:00:00 PM

Valid to:
12/3/2014 3:59:59 PM

Subject:
CN=Outfox Tv Productions Pty Ltd, O=Outfox Tv Productions Pty Ltd, STREET=129 Robertson Street, L=Fortitude Valley, S=Qld, PostalCode=4006, C=AU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0DB9E809D891B3D1DE926581A15676EA

File PE Metadata
Compilation timestamp:
8/20/2014 11:11:31 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:BhNBBIeaPvrVCm7MA5qzFAZI1Ms/fSx4wsjboD8SnfNl7K8:B/BCTxR7LqziZI1Ms/fC36Ezn+8

Entry address:
0x13986

Entry point:
E8, A4, 9C, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 57, 33, DB, 6A, 07, 33, C0, 59, 8D, 7D, E4, 89, 5D, E0, F3, AB, 39, 5D, 14, 75, 18, E8, 1C, 0A, 00, 00, C7, 00, 16, 00, 00, 00, E8, 87, 1B, 00, 00, 83, C8, FF, E9, 90, 00, 00, 00, 8B, 7D, 10, 56, 8B, 75, 0C, 3B, FB, 74, 19, 3B, F3, 75, 15, E8, F5, 09, 00, 00, C7, 00, 16, 00, 00, 00, E8, 60, 1B, 00, 00, 83, C8, FF, EB, 6B, B8, FF, FF, FF, 7F, 89, 45, E4, 3B, F8, 77, 03, 89, 7D, E4, FF, 75, 1C, 8D, 45, E0, FF, 75, 18, C7, 45, EC, 42...
 
[+]

Entropy:
6.5200

Code size:
150.5 KB (154,112 bytes)

Service
Display name:
OutfoxTvUpdater

Type:
Win32OwnProcess, InteractiveProcess


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to li963-234.members.linode.com  (45.33.9.234:80)

Remove OutfoxTvUpdater.exe - Powered by Reason Core Security