searchupdater.exe

The application searchupdater.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from s3.amazonaws.com. While running, it connects to the Internet address server-205-251-251-47.jfk5.r.cloudfront.net on port 80 using the HTTP protocol.
MD5:
05375384f84745e89dba23b7d8c2872b

SHA-1:
74f294073c3cfca8cc51daf34509ae98680f9529

SHA-256:
57013edca6865a4b6a08809ac5933f9325916854c3bc52f1599ae1bb42ee08f5

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 11:04:43 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.VOPackage
2015.10.27

Avira AntiVirus
ADWARE/ConvertAd.A.3157
8.3.2.2

Arcabit
PUP.Adware.ConvertAd
1.0.0.585

Baidu Antivirus
Adware.Win32.Vopak
4.0.3.151130

K7 AntiVirus
Riskware
13.212.17853

Kaspersky
not-a-virus:AdWare.Win32.Vopak
14.0.0.1041

Panda Antivirus
Generic Suspicious
15.11.30.08

Vba32 AntiVirus
AdWare.Vopak
3.12.26.4

File size:
229 KB (234,534 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\searchupdater.exe

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:ce34OPmHHhOLsT3W2TgXx5F4+2EwoYHyNJFh:bPmHzS5F4+2FofNbh

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file searchupdater.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-192-54-165.jfk6.r.cloudfront.net  (54.192.54.165:80)

TCP (HTTP):
Connects to server-205-251-251-47.jfk5.r.cloudfront.net  (205.251.251.47:80)

TCP (HTTP):
Connects to ec2-54-225-244-49.compute-1.amazonaws.com  (54.225.244.49:80)

TCP (HTTP):
Connects to ec2-52-1-45-42.compute-1.amazonaws.com  (52.1.45.42:80)

TCP (HTTP):
Connects to dl23.clickmein.com  (50.7.74.18:80)

Remove searchupdater.exe - Powered by Reason Core Security