updater.exe

Data Beat Solutions, LLC

Part of the branded Injekt adware package, the updater mechanism is an auto-starting program that is desigend to update the web browser extensions and protect the executables ChromeHelper, FirefoxHelper and IeHelper so that these programs can inject advertisments and generate popups in the user's web browser. The application updater.exe by Data Beat Solutions has been detected as adware by 22 anti-malware scanners. While running, it connects to the Internet address server-54-192-159-82.sin3.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
Updater  (signed by Data Beat Solutions, LLC)

Product:
Updater

Description:
Updater service

Version:
1, 0, 0, 1

MD5:
fb13fc6c77cb728e94e410aaa781fe5c

SHA-1:
b8d6f1336a2ce5cae3de6f00ae9ba575c1ee0187

SHA-256:
e045b6486f753711d2ffe49728185fd6e5daeb9f9f7cb493934c563c530615f5

Scanner detections:
22 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/25/2024 11:50:02 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.NUE
873

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

avast!
Win32:TubeDim-A [PUP]
2014.9-140915

Bitdefender
Adware.Agent.NUE
1.0.20.1290

Bkav FE
W32.Clod4a8.Trojan
1.3.0.4613

Boost by Reason
Optional.DataBeatSolutions.H
188838

Dr.Web
Adware.Plugin.130
9.0.1.0258

Emsisoft Anti-Malware
Adware.Agent.NUE
8.14.09.15.10

F-Secure
Adware.Agent.NUE
11.2014-15-09_2

G Data
Win32.Application.TubeDimmer
14.9.22

IKARUS anti.virus
AdWare.Agent
t3scan.2.2.29

Malwarebytes
PUP.Optional.TubeDimmer
v2014.09.15.10

McAfee
Artemis!FB13FC6C77CB
5600.7228

MicroWorld eScan
Adware.Agent.NUE
15.0.0.774

Norman
Malware
11.20140206

nProtect
Adware.Agent.NUE
14.02.02.01

Reason Heuristics
PUP.DataBeatSolutions.H
14.8.8.0

Sophos
Search Donkey
4.97

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10358

Trend Micro House Call
TROJ_GEN.F47V0115
7.2.37

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

VIPRE Antivirus
SearchDonkey
23956

File size:
290.4 KB (297,352 bytes)

Product version:
1, 0, 0, 1

Original file name:
updater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\updater\updater.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/3/2013 8:00:00 PM

Valid to:
6/4/2014 7:59:59 PM

Subject:
CN="Data Beat Solutions, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Data Beat Solutions, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5D5E53357F69EB288E21F6DAE0D015A6

File PE Metadata
Compilation timestamp:
10/9/2013 4:46:36 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:5FoYdZ2hhRl2lWA8s/25fwuGgp1GWVQWF/:5qwZ2PRAlAs/Id5DMWF/

Entry address:
0x1C477

Entry point:
E8, 46, 96, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, 3C, D4, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, A1, 30, AB, 43, 00, 33, C5, 89, 45, FC, 8B, 55, 18, 53, 33, DB, 56, 57, 3B, D3, 7E, 1F, 8B, 45, 14, 8B, CA, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, C2, 2B, C1, 48, 3B, C2, 7D, 01, 40, 89, 45, 18, 89, 5D, F8, 39, 5D, 24, 75, 0B, 8B, 45, 08, 8B, 00, 8B, 40, 04, 89, 45, 24, 8B, 35, 4C, 01, 43, 00...
 
[+]

Entropy:
6.4281

Code size:
187.5 KB (192,000 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-218-62-24.us-west-2.compute.amazonaws.com  (54.218.62.24:80)

TCP (HTTP):
Connects to server-54-192-159-231.sin3.r.cloudfront.net  (54.192.159.231:80)

TCP (HTTP):
Connects to ec2-52-42-90-80.us-west-2.compute.amazonaws.com  (52.42.90.80:80)

TCP (HTTP):
Connects to ec2-52-32-118-15.us-west-2.compute.amazonaws.com  (52.32.118.15:80)

TCP (HTTP):
Connects to server-54-192-159-82.sin3.r.cloudfront.net  (54.192.159.82:80)

TCP (HTTP):
Connects to server-54-192-159-74.sin3.r.cloudfront.net  (54.192.159.74:80)

TCP (HTTP):
Connects to server-54-192-159-58.sin3.r.cloudfront.net  (54.192.159.58:80)

TCP (HTTP):
Connects to server-54-192-159-174.sin3.r.cloudfront.net  (54.192.159.174:80)

TCP (HTTP):
Connects to server-54-192-159-165.sin3.r.cloudfront.net  (54.192.159.165:80)

TCP (HTTP):
Connects to server-54-192-159-157.sin3.r.cloudfront.net  (54.192.159.157:80)

TCP (HTTP):
Connects to server-54-192-159-122.sin3.r.cloudfront.net  (54.192.159.122:80)

TCP (HTTP):
Connects to ec2-54-186-84-255.us-west-2.compute.amazonaws.com  (54.186.84.255:80)

Remove updater.exe - Powered by Reason Core Security