phoenix browser updater.exe

OOO

The application phoenix browser updater.exe by OOO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. While running, it connects to the Internet address browser.gchost.ru on port 80 using the HTTP protocol.
Publisher:
OOO   (signed and verified)

MD5:
2cb69df073a7a59b3c146899b0d276a3

SHA-1:
00b3d63588354026ffb1fc81806e3d928dda64dd

SHA-256:
8d86cd02dbb0d9010dd2f9bdb575535c5ab80430941164381ab76c7caabfd12b

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/28/2024 4:12:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.6.22.13

File size:
746.1 KB (764,024 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\phoenix browser updater\phoenix browser updater.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/17/2016 7:00:00 AM

Valid to:
6/18/2017 6:59:59 AM

Subject:
CN="OOO ""TAU-SOFT""", O="OOO ""TAU-SOFT""", STREET="90/1, Lermontova street", L=Irkutsk, S=Irkutskaya obl., PostalCode=664074, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FCB6D59EED102D79C70947444AC2CE24

File PE Metadata
Compilation timestamp:
6/22/2016 3:51:39 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
12288:peHfGchTGCNpVmOdCMlJqdTbHWu4gW/WLTOQLBP5wGNcROFsUqY0TVI0Br579SuF:OhGqZJqdTbHWurlmQLBf0OFZmpl7K

Entry address:
0x2C66E

Entry point:
E8, D8, 09, 00, 00, E9, 80, FE, FF, FF, E9, 87, FD, FF, FF, 55, 8B, EC, FF, 75, 08, E8, F0, FF, FF, FF, 59, 5D, C3, 6A, 0C, 68, 10, 08, 48, 00, E8, 59, 09, 00, 00, C6, 45, E7, 00, 8B, 5D, 0C, 8B, C3, 8B, 7D, 10, 0F, AF, C7, 8B, 75, 08, 03, F0, 89, 75, 08, 83, 65, FC, 00, 8B, C7, 4F, 89, 7D, 10, 85, C0, 74, 14, 2B, F3, 89, 75, 08, 8B, 4D, 14, E8, 1A, 03, 00, 00, 8B, CE, FF, 55, 14, EB, E2, B0, 01, 88, 45, E7, C7, 45, FC, FE, FF, FF, FF, E8, 14, 00, 00, 00, E8, 50, 09, 00, 00, C2, 10, 00, 8B, 7D, 10, 8B, 5D...
 
[+]

Code size:
415 KB (424,960 bytes)

Scheduled Task
Task name:
Phoenix Browser Updater

Trigger:
Daily (Runs daily at 20:02)


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to browser.gchost.ru  (148.251.182.43:80)

Remove phoenix browser updater.exe - Powered by Reason Core Security