updater.exe

SIN PERFUMS UNITED, S.L.

The application updater.exe by SIN PERFUMS UNITED, S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Software updater’.
Publisher:
SIN PERFUMS UNITED, S.L.  (signed and verified)

MD5:
f8df82d56cc0e816c401df20ae3c6c44

SHA-1:
38a9b06fe9db384699be3aab7a15060910bc1a4d

SHA-256:
b45f01320f56d051458cf54a0418cb195c90d55e372ba6606d050d25b7872e96

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/20/2024 1:15:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SINPERFUMSUNITED (M)
16.2.12.19

File size:
84.7 KB (86,712 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\freesoftwareupdater\updater.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/16/2012 2:00:00 AM

Valid to:
8/17/2013 1:59:59 AM

Subject:
CN="SIN PERFUMS UNITED, S.L.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="SIN PERFUMS UNITED, S.L.", L=Castellon de la Plana, S=Castellon, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
61B16E61A5B72BF41E64ED8032D9A4A8

File PE Metadata
Compilation timestamp:
2/19/2012 4:01:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
1536:m0Sfpezn0Np/wYMMSmtSK/YVeCW6OqJQDRS6ZBXdp+lXExLhVNn+qJ9zA:3Win0/wpMSmMK8bWQ8RSgBNIGphn+qJu

Entry address:
0x434E0

Entry point:
60, BE, 15, D0, 43, 00, 8D, BE, EB, 3F, FC, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
28 KB (28,672 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Software updater

Command:
"C:\users\{user}\appdata\roaming\freesoftwareupdater\updater.exe" -h httC:\neoupdater.com\


Remove updater.exe - Powered by Reason Core Security