updtr.exe

The executable updtr.exe has been detected as malware by 28 anti-virus scanners.
Version:
1.1.2.7

MD5:
63d6a5af56cc4112340cdede8329a57f

SHA-1:
1bb58e3318c48b2a0cf6f8f4ad2f4d8f71f98203

SHA-256:
9685da6ba879aa1c1016b4a743cdb12a1fb748be68e1347db358aad7d0ef32ba

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/18/2024 3:27:12 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1598620
578

Avira AntiVirus
TR/Rogue.1598620
7.11.141.188

avast!
Win32:Malware-gen
2014.9-150707

AVG
CoinMiner
2016.0.3056

Baidu Antivirus
Trojan.Win32.Badur
4.0.3.1577

Bitdefender
Trojan.GenericKD.1598620
1.0.20.940

Comodo Security
UnclassifiedMalware
18066

Dr.Web
Trojan.DownLoader9.42444
9.0.1.0188

Emsisoft Anti-Malware
Trojan.GenericKD.1598620
8.15.07.07.03

ESET NOD32
MSIL/CoinMiner.IQ (variant)
9.9648

Fortinet FortiGate
W32/Badur.GZEL!tr
7/7/2015

F-Secure
Trojan.GenericKD.1598620
11.2015-07-07_3

G Data
Trojan.GenericKD.1598620
15.7.24

IKARUS anti.virus
Trojan.Win32.Badur
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.176.11684

Kaspersky
Trojan.Win32.Badur
14.0.0.1774

Malwarebytes
Backdoor.Agent.UPD
v2015.07.07.03

McAfee
RDN/Generic.grp!gz
5600.6712

MicroWorld eScan
Trojan.GenericKD.1598620
16.0.0.564

NANO AntiVirus
Trojan.Win32.Badur.cuzdvc
0.28.0.59048

nProtect
Trojan.GenericKD.1598620
14.04.07.01

Panda Antivirus
Generic Malware
15.07.07.03

Qihoo 360 Security
HEUR/Malware.QVM03.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_SPNV.01C914
7.2.188

Trend Micro
TROJ_SPNV.01C914
10.465.07

Vba32 AntiVirus
Trojan.Badur
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
28115

File size:
210 KB (215,040 bytes)

Product version:
1.1.2.7

Original file name:
WinRAR.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\updatr32\updtr.exe

File PE Metadata
Compilation timestamp:
3/7/2014 1:28:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:cBu5Kph1k+U3CwSEEElc2YZprxft3wAGXqW/J9Ql3w6K4cSYcBGwEPFsPByFW/U:epJd0Y3FVgBLJCl3wF4c8BGXP0U

Entry address:
0x32A62

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
195 KB (199,680 bytes)

Remove updtr.exe - Powered by Reason Core Security