DS4Updater.exe

DS4Updater

The application DS4Updater.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. The file has been seen being downloaded from ds4windows.com.
Product:
DS4Updater

Version:
1.1.3

MD5:
a124b02458d225509de81b0aecc1dba9

SHA-1:
7a07dec28f9259a5de3dc66eda34ea9013603341

SHA-256:
c738fee4a2cc7a7d297248cd79df411e026aacc2d1fa2b41f0580ed1c2c344fe

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 5:43:17 PM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
QVM03.0.Malware.Gen
1.0.0.1077

Reason Heuristics
Adware.Eorezo.RE (M)
16.12.8.10

File size:
560 KB (573,440 bytes)

Product version:
1.1.3

Copyright:
Copyright © Jays2Kings 2014, 2015

Original file name:
DS4Updater.exe

File type:
Executable application (Win64 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ds4updater.exe

File PE Metadata
Compilation timestamp:
11/27/2015 9:36:38 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
48.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:SaRJ7sKAAAAAWAAAAAWAAAAARAAAAAAAAAAAANAAAAAAAAAAAANAAAAAAAAAAAAm:SaRJ

Entry address:
0x76556

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
3.2142

Code size:
465.5 KB (476,672 bytes)

The file DS4Updater.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to s3-1-w.amazonaws.com  (52.216.32.32:443)

Remove DS4Updater.exe - Powered by Reason Core Security