downloader.exe

MY SECURITY CENTER LTD

The application downloader.exe, “MYSecurityCenter Update Downloader” by MY SECURITY CENTER has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address lithium.mysecuritycenter.com on port 80 using the HTTP protocol.
Publisher:
MYSecurityCenter  (signed by MY SECURITY CENTER LTD)

Product:
MYSecurityCenter

Description:
MYSecurityCenter Update Downloader

Version:
1.0.30.345 95505

MD5:
c99a5ce9eed120d4c1f448aa477c1f6c

SHA-1:
5236eac6546d60738634788e9b361f15bdf8d8f0

SHA-256:
62ca6f986241999e7d2faede2a164d0a8b8f3fbabaa6e5998bc9986f121cbfa9

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/14/2024 11:54:07 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
Win64.Generic
16.5.8.16

File size:
400.3 KB (409,944 bytes)

Product version:
1.0.30.345 95505

Copyright:
@ MYSecurityCenter

Original file name:
downloader.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mysecuritycenter\myinternetsecurity\downloader.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
5/16/2012 7:00:00 PM

Valid to:
7/21/2015 7:00:00 AM

Subject:
CN=MY SECURITY CENTER LTD, O=MY SECURITY CENTER LTD, L=West Drayton, C=GB

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
02B405245A6E01DE7848F7C55FC3BCC7

File PE Metadata
Compilation timestamp:
10/25/2012 9:31:27 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
6144:O/gsyLQQuGCQdUY1Ld9bFnV/U5//98n4G+ZV/+cNXqqadk2UqQy4iacqQ:OosCQQvBB1LjdVoH9QctICSTp

Entry address:
0x2E9E8

Entry point:
48, 83, EC, 28, E8, C7, E5, 00, 00, 48, 83, C4, 28, E9, 56, FE, FF, FF, CC, CC, 40, 53, 48, 83, EC, 20, BA, 08, 00, 00, 00, 8D, 4A, 18, E8, 7D, 28, 00, 00, 48, 8B, C8, 48, 8B, D8, E8, CA, 58, 00, 00, 48, 89, 05, EF, 20, 03, 00, 48, 89, 05, E0, 20, 03, 00, 48, 85, DB, 75, 05, 8D, 43, 18, EB, 06, 48, 83, 23, 00, 33, C0, 48, 83, C4, 20, 5B, C3, CC, CC, 48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 48, 89, 7C, 24, 18, 41, 54, 41, 55, 41, 56, 48, 83, EC, 20, 4C, 8B, F1, E8, 13, 63, 00, 00, 90, 48, 8B, 0D, A7, 20, 03...
 
[+]

Entropy:
6.2074

Code size:
290 KB (296,960 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to lithium.mysecuritycenter.com  (188.40.51.149:80)

Remove downloader.exe - Powered by Reason Core Security