update.exe

The executable update.exe has been detected as malware by 27 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download.idmsilent.net.
MD5:
7c8d0ba13b4b2a72175eb47176b2d9b0

SHA-1:
10339ccac04773de3b5ef8330c54662b2a879796

SHA-256:
8b5a57fb83fa41fc6373174ee19ba9b9f610023e80391158bd6f49c2662e4c7f

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
11/23/2024 12:10:31 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.84754
352

Agnitum Outpost
Trojan.Agent
7.1.1

AhnLab V3 Security
Spyware/Win32.Agent
2015.03.04

Avira AntiVirus
TR/Injector.393216.48
7.11.213.94

avast!
MSIL:Agent-BQX [Trj]
2014.9-160217

AVG
Agent4
2017.0.2830

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.16217

Bitdefender
Gen:Variant.Zusy.84754
1.0.20.240

Bkav FE
W32.RoaleteyLTE.Trojan
1.3.0.6379

Comodo Security
UnclassifiedMalware
21284

Dr.Web
Trojan.DownLoader9.30057
9.0.1.048

Emsisoft Anti-Malware
Gen:Variant.Zusy.84754
8.16.02.17.12

ESET NOD32
Win32/Agent.VOE
10.11265

Fortinet FortiGate
W32/Agent.VOE!tr
2/17/2016

F-Secure
Packed:MSIL/SmartIL.A
11.2016-17-02_4

G Data
Gen:Variant.Zusy.84754
16.2.25

K7 AntiVirus
Trojan
13.200.15148

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.647

Malwarebytes
Backdoor.Agent.LDGen
v2016.02.17.12

McAfee
W32/Worm-FSD!Gamarue
5600.6486

MicroWorld eScan
Gen:Variant.Zusy.84754
17.0.0.144

NANO AntiVirus
Trojan.Win32.Foxhiex.dhxzyz
0.30.0.296

Norman
Suspicious_Gen4.FWPLS
11.20160217

Panda Antivirus
Trj/CI.A
16.02.17.12

Qihoo 360 Security
HEUR/Malware.QVM03.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic
38102

File size:
383 KB (392,192 bytes)

File type:
Executable application (Win32 EXE)

Language:
Polish (Poland)

Common path:
C:\users\{user}\appdata\local\temp\update.exe

File PE Metadata
Compilation timestamp:
2/25/2014 7:32:40 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:H2tDOzKBavVWjNyn9obgx83Eb8KWFZpkIiq8cjHLIwyAY6c0WZ/OBkOteCTdsnug:WtyvA49oUxoEb8KKZocjHEhAVhWZ2aOo

Entry address:
0x6107E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8681

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
380.5 KB (389,632 bytes)

The file update.exe has been seen being distributed by the following URL.

Remove update.exe - Powered by Reason Core Security