produpd.exe

Vest's software office

Vest' Ltd

The executable produpd.exe, “Software updater service” has been detected as malware by 13 anti-virus scanners. While running, it connects to the Internet address col0-mc4-f.col0.hotmail.com on port 25.
Publisher:
Vest' Ltd

Product:
Vest's software office

Description:
Software updater service

Version:
2.2.0.99

MD5:
306e5f1a18c05d894bbc979ec32183a0

SHA-1:
d6a80cdb16f860c2cb3483789e3de76597fce187

SHA-256:
6fb369dd9e10d8c3bfe85ebad2fadd851f772666b90cb136bf3d0d12f27b9ba7

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
8/6/2025 12:15:01 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.113697
99

AhnLab V3 Security
Trojan/Win32.Generic.C1612235
3.8.1.15

Arcabit
Trojan.Strictor.D1BC21
1.0.0.779

Bitdefender
Gen:Variant.Strictor.113697
1.0.20.1505

Emsisoft Anti-Malware
Gen:Variant.Strictor.113697
8.16.10.27.12

ESET NOD32
Win32/Glupteba.AP (variant)
10.14346

Fortinet FortiGate
W32/Glupteba.AO!tr
10/27/2016

F-Secure
Gen:Variant.Strictor.113697
11.2016-27-10_5

G Data
Gen:Variant.Strictor.113697
16.10.25

IKARUS anti.virus
Trojan.Win32.Glupteba
t3scan.2.1.16.0

MicroWorld eScan
Gen:Variant.Strictor.113697
17.0.0.903

Panda Antivirus
Trj/Genetic.gen
16.10.27.12

Qihoo 360 Security
HEUR/QVM10.1.0000.Malware.Gen
1.0.0.1120

File size:
625 KB (640,000 bytes)

Product version:
2.2.0.1

Copyright:
Copyright (C) 2016

Original file name:
produpd.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\vdi\shared\product updater\produpd.exe

File PE Metadata
Compilation timestamp:
10/27/2016 4:13:30 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
12288:LNfZFYJxQjcQ8qhuwm0bKRXO595Nk9hocJY9O0Y9+HZXozwlh:xfiEhuwRKRXORcJr0YwHZ4zC

Entry address:
0x2FA2C

Entry point:
E8, 6A, 09, 00, 00, E9, 8E, FE, FF, FF, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, F2, C3, 8B, 4D, F0, 33, CD, F2, E8, 79, F8, FF, FF, F2, E9, DA, FF, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 78, D0, 48, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, F2, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 78, D0, 48, 00...
 
[+]

Code size:
449.5 KB (460,288 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to srv81-165-240-87.vk.com  (87.240.165.81:443)

TCP:
Connects to interviewder.net  (91.203.5.26:444)

TCP (HTTP):
Connects to radaris.com  (69.90.124.140:80)

TCP:
Connects to nodomen.ru  (185.31.161.198:8000)

TCP:
Connects to f755.fuchsia.servdiscount-customer.com  (85.14.243.91:8000)

TCP (WHOIS):
Connects to whois.hkg5.verisign.com  (199.7.61.74:43)

TCP (WHOIS):
Connects to whois.domain-registry.nl  (94.198.154.138:43)

TCP (WHOIS):
Connects to whois.denic.de  (81.91.170.6:43)

TCP (HTTP SSL):
Connects to o2.mail.ru  (217.69.139.61:443)

TCP:
Connects to icebergcone.com  (91.142.85.224:8000)

TCP (WHOIS):
Connects to whois.ripe.net  (193.0.6.135:43)

TCP (HTTP):
Connects to webmail.socsoter.com  (74.208.123.179:80)

TCP (HTTP SSL):
Connects to s35.friendhosting.net  (185.82.216.53:443)

TCP:
Connects to ppp78-37-12-10.pppoe.avangarddsl.ru  (78.37.12.10:4899)

TCP (HTTP):
Connects to node001.adplexity.com  (107.6.167.194:80)

TCP (WHOIS):
Connects to nb-185-3-93-80.london.nodebalancer.linode.com  (185.3.93.80:43)

TCP (SMTP):
Connects to mta-v1.mail.vip.bf1.yahoo.com  (66.196.118.33:25)

TCP (SMTP):
Connects to mail.suddenlinkmail.com  (208.180.40.132:25)

TCP (HTTP):
Connects to ip248.152.odnoklassniki.ru  (217.20.152.248:80)

TCP (HTTP SSL):
Connects to edge-z-m-mini-shv-01-frt3.facebook.com  (31.13.92.37:443)

Remove produpd.exe - Powered by Reason Core Security