updater.exe

Marc Skawran

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘donation_updater’.
Publisher:
Marc Skawran  (signed and verified)

MD5:
cac1e6d5fd3edb62995556a0c1316306

SHA-1:
8f380f718dff5a4b2b95b25d0c5bf03617ec2b35

SHA-256:
3f5863b9b59bae0d04b7adbf017d773b84dc98e1ad3476ba5355d1d8ce6ff656

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:10:42 PM UTC  (today)

File size:
52.1 KB (53,352 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
2/4/2014 1:23:08 PM

Valid to:
2/5/2016 9:22:40 PM

Subject:
E=m.skawran@networksys.org, CN=Marc Skawran, L=Tagum City, S=Davao del Norte, C=PH, Description=uwZYx59gN3N1gr77

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
0CDB

File PE Metadata
Compilation timestamp:
12/6/2009 5:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:PpgpHzb9dZVX9fHMvG0D3XJcM9gkqIzjbanyyDzl:xgXdZt9P6D3XJcMe5KUD5

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.1005

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
donation_updater

Command:
C:\users\{user}\documents\updater\updater.exe


Scan updater.exe - Powered by Reason Core Security