updater28430.exe

Savings Ship

Engaging Apps

This is part of a distribution package that is classified as adware distributed by 50onRed. This adware is used to interact with the installed web browsers and inject ads and modify the default search and homepages. The application updater28430.exe by Engaging Apps has been detected as adware by 6 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered by a time event.
Publisher:
Innovative Apps  (signed by Engaging Apps)

Product:
Savings Ship

Description:
Savings Ship exe

Version:
1000.1000.1000.1000

MD5:
9135c0d41dfadda9a822762663a0f214

SHA-1:
b0de1a592df90d05f646144222b78d51e2a22d6a

SHA-256:
ab1a8d69d8d536b328d991a3f03fd8762dfd3c2359af079935e0305b82f61ce0

Scanner detections:
6 / 68

Status:
Adware

Explanation:
May modify the web browser's settings including changing the homepage and search provider in addition to delivering ads (by injecting banner and text-links directly in the webpage).

Analysis date:
4/26/2024 8:48:21 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Dropper-gen [Drp]
141025-0

ESET NOD32
Win32/Toolbar.CrossRider.C potentially unwanted application
7.0.302.0

K7 AntiVirus
Unwanted-Program
13.185.13805

Malwarebytes
PUP.Optional.SavingsShip.A
v2014.10.25.05

Reason Heuristics
PUP.Task.EngagingApps.M
14.10.25.17

VIPRE Antivirus
Threat.4750557
34232

File size:
214.4 KB (219,528 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
Savings Ship.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\updater28430\updater28430.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/3/2013 8:00:00 PM

Valid to:
6/4/2014 7:59:59 PM

Subject:
CN=Engaging Apps, O=Engaging Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
632EEBD9B987BC680D444D8675A26545

File PE Metadata
Compilation timestamp:
10/14/2013 6:52:04 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:ueGE+NVQ18CsQ08QD4UA4TuRIUhUei6JMqJCsfDnGnmG/os5:hGPNtCt0X4UA4TuBhUei6JMqdmws

Entry address:
0x16881

Entry point:
E8, D5, 8F, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, 92, E0, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, A1, 20, 46, 43, 00, 33, C5, 89, 45, FC, 8B, 55, 18, 53, 33, DB, 56, 57, 3B, D3, 7E, 1F, 8B, 45, 14, 8B, CA, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, C2, 2B, C1, 48, 3B, C2, 7D, 01, 40, 89, 45, 18, 89, 5D, F8, 39, 5D, 24, 75, 0B, 8B, 45, 08, 8B, 00, 8B, 40, 04, 89, 45, 24, 8B, 35, E0, B0, 42, 00...
 
[+]

Entropy:
6.4598

Code size:
166 KB (169,984 bytes)

Scheduled Task
Task name:
Updater28430.exe

Trigger:
Time (Next runs on 10/25/2014 at 9:42 PM)


Remove updater28430.exe - Powered by Reason Core Security