driverupdatersetup-2.0.0.4706.exe

ROSTPAY LLC

The software installer program will bundle additional offers in its setup routine. The application driverupdatersetup-2.0.0.4706.exe by ROSTPAY has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from eudn.carambis.com.
Publisher:
ROSTPAY LLC  (signed and verified)

MD5:
afb03a4735e3765fa7a0b0f6e3deacb1

SHA-1:
2c86ce170c8050f822e1ac985c32b484346fc000

SHA-256:
e4915d1add0605867192e1d66b9a44763f6809d585dfe9409f0434576a601128

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 8:38:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.MediaFrog.ROSTPAY.Installer (M)
16.1.11.5

File size:
14.8 MB (15,518,696 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\driverupdatersetup-2.0.0.4706.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
12/14/2010 10:00:00 PM

Valid to:
12/14/2012 9:59:59 PM

Subject:
CN=ROSTPAY LLC, OU=Software Development, O=ROSTPAY LLC, L=Rostov-on-Don, S=RU, C=RU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
31F74FDD9FABF79D4C202D79A0DA4146

File PE Metadata
Compilation timestamp:
9/26/2011 10:21:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
393216:LpFkbiOjELX1dqGNkEYfQmbO7V4p/LECeqkcm:LrROjET14GNkVf1lRLECeqkcm

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file driverupdatersetup-2.0.0.4706.exe has been seen being distributed by the following URL.

Remove driverupdatersetup-2.0.0.4706.exe - Powered by Reason Core Security