downloader.exe

MY SECURITY CENTER LTD

The application downloader.exe, “MYSecurityCenter Update Downloader” by MY SECURITY CENTER has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address lithium.mysecuritycenter.com on port 80 using the HTTP protocol.
Publisher:
MYSecurityCenter  (signed by MY SECURITY CENTER LTD)

Product:
MYSecurityCenter

Description:
MYSecurityCenter Update Downloader

Version:
1.0.30.345 95505

MD5:
ef5a8d7f569d5e8694a35ea1569f9534

SHA-1:
0719c52c0c8732a9bf6a252f66a3bb81f11086c5

SHA-256:
662aa4068c7fb54d3eedfbd9d25a4711c4a018e0d235634ca11e3787a843c149

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 12:15:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic.MYSECURITYCENTER.Meta
15.6.13.12

File size:
299.8 KB (307,032 bytes)

Product version:
1.0.30.345 95505

Copyright:
@ MYSecurityCenter

Original file name:
downloader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mysecuritycenter\myinternetsecurity\downloader.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
5/17/2012 10:00:00 AM

Valid to:
7/21/2015 10:00:00 PM

Subject:
CN=MY SECURITY CENTER LTD, O=MY SECURITY CENTER LTD, L=West Drayton, C=GB

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
02B405245A6E01DE7848F7C55FC3BCC7

File PE Metadata
Compilation timestamp:
10/26/2012 1:31:05 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
6144:S1BCCXgPbArv+czoLHhV1cvUtMLbuEAB8:SPC1DArvToLHhV1cvU6n9

Entry address:
0x20DCE

Entry point:
E8, 17, D8, 00, 00, E9, A5, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 56, 57, FF, 35, 8C, 7B, 44, 00, E8, 4E, 57, 00, 00, FF, 35, 88, 7B, 44, 00, 8B, F8, 89, 7D, FC, E8, 3E, 57, 00, 00, 8B, F0, 59, 59, 3B, F7, 0F, 82, 83, 00, 00, 00, 8B, DE, 2B, DF, 8D, 43, 04, 83, F8, 04, 72, 77, 57, E8, 66, D8, 00, 00, 8B, F8, 8D, 43, 04, 59, 3B, F8, 73, 48, B8, 00, 08, 00, 00, 3B, F8, 73, 02, 8B, C7, 03, C7, 3B, C7, 72, 0F, 50, FF, 75, FC, E8, 48, 25, 00, 00, 59, 59, 85, C0, 75, 16, 8D, 47, 10, 3B, C7, 72, 40, 50, FF, 75...
 
[+]

Entropy:
6.4838

Code size:
227.5 KB (232,960 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to lithium.mysecuritycenter.com  (188.40.51.149:80)

TCP (HTTP):
Connects to mybd-oth2-hzn  (88.198.157.124:80)

Remove downloader.exe - Powered by Reason Core Security