ultraupdater.exe

The executable ultraupdater.exe has been detected as malware by 14 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from kamilbe5.bget.ru.
MD5:
f9583c9e481286ce7275c59506e24b5c

SHA-1:
9a8d9d3fa662a008c092faec97991b7082aa90ea

SHA-256:
e83cea85e7558d508ea64bdcaec383daf3f6c29ae3a114193f214d302de9bf4b

Scanner detections:
14 / 68

Status:
Malware

Analysis date:
12/25/2024 6:30:24 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.3423100
186

Arcabit
Trojan.Generic.D343B7C
1.0.0.741

avast!
Win32:Malware-gen
2014.9-160801

Bitdefender
Trojan.GenericKD.3423100
1.0.20.1070

Emsisoft Anti-Malware
Trojan.GenericKD.3423100
8.16.08.01.07

F-Secure
Trojan.GenericKD.3423100
11.2016-01-08_2

G Data
Trojan.GenericKD.3423100
16.8.25

IKARUS anti.virus
possible-Threat.Hacktool.Patcher
t3scan.2.1.6.0

Kaspersky
Trojan-Downloader.Win32.Small
14.0.0.-184

McAfee
Artemis!F9583C9E4812
5600.6320

MicroWorld eScan
Trojan.GenericKD.3423100
17.0.0.642

nProtect
Trojan.GenericKD.3423100
16.07.25.01

Panda Antivirus
Trj/Genetic.gen
16.08.01.07

Qihoo 360 Security
HEUR/QVM05.1.0000.Malware.Gen
1.0.0.1120

File size:
2.8 MB (2,981,376 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ultraupdater.exe

File PE Metadata
Compilation timestamp:
6/20/1992 4:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:dL/Zs+5WoW/AINquANoitTxq2yp1FwKiYYDVKc6w/GtKgxa:dLRtsouAMAv/qwvBKzw/Gtpx

Entry address:
0x131AD0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 18, 15, 53, 00, E8, 24, 50, ED, FF, A1, 6C, 73, 53, 00, 8B, 00, E8, 34, D6, F2, FF, A1, 6C, 73, 53, 00, 8B, 00, BA, 30, 1B, 53, 00, E8, 0B, D2, F2, FF, 8B, 0D, 24, 75, 53, 00, A1, 6C, 73, 53, 00, 8B, 00, 8B, 15, 98, 0C, 53, 00, E8, 23, D6, F2, FF, A1, 6C, 73, 53, 00, 8B, 00, E8, 97, D6, F2, FF, E8, 86, 2A, ED, FF, 00, 00, FF, FF, FF, FF, 14, 00, 00, 00, 4C, 65, 67, 69, 6F, 6E, 48, 61, 63, 6B, 20, 2D, 20, 55, 70, 64, 61, 74, 65, 72, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.2 MB (1,248,256 bytes)

The file ultraupdater.exe has been seen being distributed by the following URL.

Remove ultraupdater.exe - Powered by Reason Core Security