updates.exe

The executable updates.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Updates’. While running, it connects to the Internet address w.interiowo.pl on port 80 using the HTTP protocol.
MD5:
c6169544fa3688b3107258b467406cd3

SHA-1:
6bbd795bfee6f72e3ca1eb00b0c33ee17c80837f

SHA-256:
3f038d228d2d7a9eae347dac869eceae3d4a90fa8863edf442613ad076bb8ac6

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
5/2/2024 9:19:13 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Trojan.Downloader.UP (M)
17.1.30.16

File size:
220 KB (225,280 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
1/24/2011 4:29:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x17EC

Entry point:
69, F6, 56, 9E, 4D, E5, 8D, 15, 6E, BC, 93, 77, 0C, 9D, 4A, 21, DE, EB, 04, 85, C7, 32, F2, 78, 08, 69, C8, FC, 75, 3D, 10, 86, D4, 08, EF, F3, 81, F5, 67, 0C, 00, 00, 89, DE, C7, C6, FD, F4, 73, 19, 0D, FA, 31, C9, F2, 69, CB, 61, 21, 75, B8, C6, C4, 02, EB, 06, 0F, BE, EF, B6, 88, 43, 85, DF, 72, 0C, 0F, B7, C7, 0F, B7, D7, 69, F9, A8, F3, 56, C1, 87, D3, E8, 17, 00, 00, 00, 20, DA, 84, F1, 0F, B6, F3, 85, FD, 03, ED, 81, FB, A2, D9, 00, 00, 71, 04, 12, CD, 84, CB, 38, CE, FE, C9, F6, C7, 93, 84, E5, F3...
 
[+]

Entropy:
7.2906

Code size:
36 KB (36,864 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Updates

Command:
C:\updates.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to w.interiowo.pl  (217.74.66.161:80)

TCP (HTTP):
Connects to dns1.ru-tld.ru  (37.187.83.72:80)

TCP (HTTP):
Connects to 89-19-29-112.cizgi.net.tr  (89.19.29.112:80)

Remove updates.exe - Powered by Reason Core Security