_updater.exe

Creative Island Media, LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser. Part of the Injekt brand of unwanted programs. The application _updater.exe by Creative Island Media has been detected as adware by 17 anti-malware scanners. While running, it connects to the Internet address update.betterxperience.com on port 80 using the HTTP protocol.
Publisher:
Updater  (signed by Creative Island Media, LLC)

Product:
Updater

Description:
Updater service

Version:
1, 0, 0, 1

MD5:
1d0d2a47530a3a28325498ac73bc0aba

SHA-1:
064f0abc5737448458b50382fb84d7e9b6001165

SHA-256:
c2395606ab93696a323eeb4e5218e1c27aee2f70d5e00ff78e13a5f532af9036

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/26/2024 1:20:22 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.NUR
641

avast!
Win32:TubeDim-A [PUP]
2014.9-150803

Bitdefender
Adware.Agent.NUR
1.0.20.620

Bkav FE
W32.Clod4a8.Trojan
1.3.0.4613

Dr.Web
Adware.Plugin.130
9.0.1.0215

Emsisoft Anti-Malware
Adware.Agent.NUE
8.15.05.04.09

F-Secure
Adware.Agent.NUE
11.2015-04-05_2

G Data
Win32.Application.TubeDimmer
15.5.22

herdProtect (fuzzy)
2015.8.3.4

IKARUS anti.virus
AdWare.Agent
t3scan.2.2.29

Malwarebytes
PUP.Optional.TubeDimmer
v2015.08.03.04

MicroWorld eScan
Adware.Agent.NUR
16.0.0.372

nProtect
Adware.Agent.NUR
14.03.21.01

Reason Heuristics
Threat.Injekt.CreativeIslandMedia
15.5.4.17

Sophos
Search Donkey
4.97

Trend Micro House Call
TROJ_GEN.F47V1106
7.2.124

VIPRE Antivirus
SearchDonkey
23956

File size:
478.4 KB (489,848 bytes)

Product version:
1, 0, 0, 1

Original file name:
updater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\application data\updater\_updater.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/20/2013 8:00:00 PM

Valid to:
5/21/2014 7:59:59 PM

Subject:
CN="Creative Island Media, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Creative Island Media, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
68F23F4D2767F6491DEA9186F2E5CB89

File PE Metadata
Compilation timestamp:
3/16/2014 9:45:21 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:f8XAeHLX4g3SpJekApezvisBMP115jDe9bqAwrP/njqdxj4:UXAeHLX4g3wgkOezlBk153e9bGrHudx0

Entry address:
0x38DC2

Entry point:
E8, B9, D1, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 3A, FE, FF, FF, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 24, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, 3C, F5, 40, 7C, 46, 00, 00, 75, 13, 56, E8, 71, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 11, E8, A2, 5A, 00, 00, 59, FF, 34, F5, 40, 7C, 46, 00, FF, 15, 88, 50, 45, 00, 5E, 5D, C3, 56, 57, BE, 40, 7C, 46, 00, 8B, FE, 53, 8B, 1F, 85, DB, 74, 17, 83, 7F...
 
[+]

Entropy:
6.4412

Code size:
334 KB (342,016 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to update.betterxperience.com  (54.218.62.24:80)

TCP (HTTP):
Connects to d.pullupdate.com  (54.230.15.37:80)

Remove _updater.exe - Powered by Reason Core Security