downloader.exe

MY SECURITY CENTER LTD

The application downloader.exe, “MYSecurityCenter Update Downloader” by MY SECURITY CENTER has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address lithium.mysecuritycenter.com on port 80 using the HTTP protocol.
Publisher:
MYSecurityCenter  (signed by MY SECURITY CENTER LTD)

Product:
MYSecurityCenter

Description:
MYSecurityCenter Update Downloader

Version:
1.0.30.374 125676

MD5:
117e28e1a463065e7b37a17a3d505f51

SHA-1:
21717b0331231fc926d882bcad659b8913ddb0a4

SHA-256:
0ac95730fe4db90532ba74431845760b363a634a5f54f69fe871e6cf9cf6424e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/14/2024 11:54:13 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.MYSECURITYCENTER
15.1.12.12

File size:
402.3 KB (411,992 bytes)

Product version:
1.0.30.374 125676

Copyright:
@ MYSecurityCenter

Original file name:
downloader.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mysecuritycenter\myinternetsecurity\downloader.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
5/17/2012 2:00:00 AM

Valid to:
7/21/2015 2:00:00 PM

Subject:
CN=MY SECURITY CENTER LTD, O=MY SECURITY CENTER LTD, L=West Drayton, C=GB

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
02B405245A6E01DE7848F7C55FC3BCC7

File PE Metadata
Compilation timestamp:
2/11/2014 11:16:46 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
6144:ijGKBJj+JxUccf1GF4mlbmso5Ej+93hIhE0hcoD8kklqQrjKGB/NT:iCKfj+/S1GDbZsEjj3DRe/NT

Entry address:
0x2ECB8

Entry point:
48, 83, EC, 28, E8, C7, E5, 00, 00, 48, 83, C4, 28, E9, 56, FE, FF, FF, CC, CC, 40, 53, 48, 83, EC, 20, BA, 08, 00, 00, 00, 8D, 4A, 18, E8, 7D, 28, 00, 00, 48, 8B, C8, 48, 8B, D8, E8, CA, 58, 00, 00, 48, 89, 05, 1F, 1E, 03, 00, 48, 89, 05, 10, 1E, 03, 00, 48, 85, DB, 75, 05, 8D, 43, 18, EB, 06, 48, 83, 23, 00, 33, C0, 48, 83, C4, 20, 5B, C3, CC, CC, 48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 48, 89, 7C, 24, 18, 41, 54, 41, 55, 41, 56, 48, 83, EC, 20, 4C, 8B, F1, E8, 13, 63, 00, 00, 90, 48, 8B, 0D, D7, 1D, 03...
 
[+]

Code size:
291 KB (297,984 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to lithium.mysecuritycenter.com  (188.40.51.149:80)

Remove downloader.exe - Powered by Reason Core Security