updatetask.exe

This is part of various InstallCore adware bundles and is designed to run daily and maintain the current state of the installed product(s) offeres (mostly unwanted adware) by connecting to a remote server for configuration instructions. The application updatetask.exe has been detected as adware by 2 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time.
MD5:
ef0dee2c132cebd6b21c3fa701b0790f

SHA-1:
984f1f9c20cfd40f543247105a7e564adb6129a8

SHA-256:
d427f20d470acd8096a174a70fc3b6035a132787f868e48db242027158b4967a

Scanner detections:
2 / 68

Status:
Adware

Explanation:
The update task for the InstallCore download manager.

Analysis date:
4/25/2024 3:40:44 AM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.Task.K
188432

Reason Heuristics
PUP.UpdateProc.Task.K
14.3.3.16

File size:
98 KB (100,352 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\digitalsites\updateproc\updatetask.exe

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:6RTPc4VB0UJpWevexv71hj5XZe7r9EgGu1R/3:6RIs0UT3WB1hFJO9E4v/3

Entry address:
0x16BCC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 74, 6B, 41, 00, E8, F8, DF, FE, FF, 33, C0, 55, 68, 54, 6C, 41, 00, 64, FF, 30, 64, 89, 20, B8, 5C, 8C, 41, 00, BA, 68, 6C, 41, 00, E8, 33, CF, FE, FF, 83, 3D, 5C, 8C, 41, 00, 00, 75, 0F, B8, 5C, 8C, 41, 00, BA, 78, 6C, 41, 00, E8, 1B, CF, FE, FF, B8, 5C, 8C, 41, 00, BA, 88, 6C, 41, 00, E8, 18, D1, FE, FF, 6A, 00, 68, 6C, 69, 41, 00, 68, B8, 6A, 41, 00, 68, EC, 6A, 41, 00, B9, 9C, 6C, 41, 00, 8B, 15, 5C, 8C, 41, 00, B8, C4, 6C, 41, 00, E8, A6, 5A, FF, FF, 33, C0, 5A, 59, 59, 64...
 
[+]

Entropy:
6.5217

Developed / compiled with:
Microsoft Visual C++

Code size:
87.5 KB (89,600 bytes)

Scheduled Task
Task name:
Digital Sites

Trigger:
Daily (Runs daily at 11:24 PM)

Action:
updatetask.exe \check


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to s3-1-w.amazonaws.com  (176.32.97.233:80)

TCP (HTTP):
Connects to ec2-54-245-249-144.us-west-2.compute.amazonaws.com  (54.245.249.144:80)

TCP (HTTP):
Connects to ec2-54-235-86-141.compute-1.amazonaws.com  (54.235.86.141:80)

TCP (HTTP):
Connects to ec2-54-225-155-49.compute-1.amazonaws.com  (54.225.155.49:80)

TCP (HTTP):
Connects to bits-lb.eqiad.wikimedia.org  (208.80.154.234:80)

Remove updatetask.exe - Powered by Reason Core Security