updater.exe

Arne Koenig

The application updater.exe by Arne Koenig has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘OpenOffice Updater’. This file is typically installed with the program OpenOffice Updater by OpenOffice. While running, it connects to the Internet address s02.argon.webspace24.de on port 80 using the HTTP protocol.
Publisher:
Arne Koenig  (signed and verified)

MD5:
88dbf6df632cad6b22186da206829639

SHA-1:
1d8ab9d406babcb9ac7af57817adfe3144d2fc26

SHA-256:
cb7fa8f321eddfaa897e15c5ed212afad6469cad88f966771ff2f824fde50423

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/6/2024 11:00:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.18.2

File size:
378.9 KB (388,000 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\openoffice updater\updater.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
8/17/2015 12:22:40 PM

Valid to:
11/4/2018 11:29:51 AM

Subject:
CN=Arne Koenig, O=Arne Koenig, L=Verden, S=Niedersachsen, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112156400F30E98EC0755AF2B124F4872F61

File PE Metadata
Compilation timestamp:
7/25/2016 2:55:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x310F

Entry point:
81, EC, 84, 01, 00, 00, 53, 56, 57, 33, DB, 68, 01, 80, 00, 00, 89, 5C, 24, 18, C7, 44, 24, 10, 98, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, A8, 70, 40, 00, FF, 15, A4, 70, 40, 00, 66, 3D, 06, 00, 74, 11, 53, E8, 7C, 2F, 00, 00, 3B, C3, 74, 07, 68, 00, 0C, 00, 00, FF, D0, BE, 98, 72, 40, 00, 56, E8, F8, 2E, 00, 00, 56, FF, 15, A0, 70, 40, 00, 8D, 74, 06, 01, 38, 1E, 75, EB, 55, 6A, 09, E8, 4F, 2F, 00, 00, 6A, 07, E8, 48, 2F, 00, 00, A3, 04, E4, 42, 00, FF, 15, 44, 70, 40, 00, 53, FF, 15, 88...
 
[+]

Code size:
24 KB (24,576 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
OpenOffice Updater

Command:
C:\users\{user}\appdata\roaming\openoffice updater\updater.exe


The file updater.exe has been discovered within the following program.

OpenOffice Updater  by OpenOffice
About 1% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to s02.argon.webspace24.de  (78.46.96.67:80)

Remove updater.exe - Powered by Reason Core Security