update.exe

Pass Revelator

The application update.exe by Pass Revelator has been detected as adware by 2 anti-malware scanners. This is a setup program which is used to install the application. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.passwordrevelator.net and multiple other hosts.
Publisher:
Pass Revelator  (signed and verified)

Version:
1.0.0.0

MD5:
2e5694d44e81dd155e21bdd2a89af51d

SHA-1:
96c9a11239ef0b8607f31e453cd04c3cc61dff80

SHA-256:
e1b079ecc622a2ff7b29c0417cdfa69a5426130f4744c87d160d172eedc29c2c

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
11/16/2024 10:28:56 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.PassRevelator
15.3.1.18

VIPRE Antivirus
Pass Revelator
38028

File size:
2.1 MB (2,251,376 bytes)

Product version:
1.0.0.0

Original file name:
update

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\update.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/12/2014 1:00:00 AM

Valid to:
10/18/2015 12:59:59 AM

Subject:
CN=Pass Revelator, O=Pass Revelator, STREET=12 rue de Bercy, L=PARIS, S=Outside United States, PostalCode=75012, C=FR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
294C0252ECCFBDBA19C238FA705964F3

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:DGUwKu/5dlHb0xn91Q2C5AVlY7SJb/UEvuF0:DGUBu/5dN+91QNAw7M79h

Entry address:
0x1AB4A8

Entry point:
55, 8B, EC, 83, C4, F0, B8, 18, AF, 5A, 00, E8, D4, BF, E5, FF, E8, EB, 3A, EC, FF, A1, C8, 8A, 5B, 00, 80, 38, 05, 75, 11, A1, 1C, 8D, 5B, 00, 83, 38, 00, 74, 07, E8, 3A, 76, FB, FF, EB, 6C, A1, C8, 8A, 5B, 00, 80, 38, 04, 75, 11, A1, 1C, 8D, 5B, 00, 83, 38, 00, 74, 07, E8, E3, 7A, FB, FF, EB, 51, A1, 8C, 8C, 5B, 00, 8B, 00, E8, 0D, 15, EC, FF, 8B, 0D, E4, 89, 5B, 00, A1, 8C, 8C, 5B, 00, 8B, 00, 8B, 15, 40, B5, 54, 00, E8, 0D, 15, EC, FF, A1, 8C, 8C, 5B, 00, 8B, 00, E8, 81, 15, EC, FF, A1, C8, 8A, 5B, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.7 MB (1,746,432 bytes)

The file update.exe has been seen being distributed by the following 2 URLs.

Remove update.exe - Powered by Reason Core Security