update.tmp

AVSoftware EOOD

The file update.tmp by AVSoftware EOOD has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
AVSoftware EOOD  (signed and verified)

Description:
Setup/Uninstall

Version:
51.1052.0.0

MD5:
0e101fb710b60db35410af9cf513cd5e

SHA-1:
7c05bc82d49ad3dddf8068e645416791914d351e

SHA-256:
f34978b519e2a0dbe84019b134ae3a4813b16fbea75295e568f26f0886dd67df

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 2:13:37 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.AVSoftware EOOD.Installer (M)
16.4.13.22

File size:
1.1 MB (1,181,792 bytes)

Language:
Language Neutral

Common path:
C:\windows\temp\{random}.tmp\update.tmp

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
2/3/2016 12:00:00 AM

Valid to:
5/2/2019 12:59:59 AM

Subject:
CN=AVSoftware EOOD, OU=IT, O=AVSoftware EOOD, L=Sofia, S=Sofia, C=BG, SERIALNUMBER=200437750, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=BG

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA - G2, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
3758D0D4E1B2569875AAACFB7F4C442A

File PE Metadata
Compilation timestamp:
7/16/2015 2:24:21 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:NEZXjiinrzY5tO+uKE3LMT0jECZQEbLBDBEnFWsyb7x9iW:KdmbjTKlD00Rl

Entry address:
0x100004

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, 57, B8, 94, DD, 4F, 00, E8, 35, 8F, F0, FF, 6A, EC, A1, 14, 3E, 50, 00, 8B, 00, 8B, 98, 70, 01, 00, 00, 53, E8, D8, 9D, F0, FF, 25, 7F, FF, FF, FF, 50, 6A, EC, A1, 14, 3E, 50, 00, 53, E8, 2D, A0, F0, FF, 33, C0, 55, 68, 7F, 00, 50, 00, 64, FF, 30, 64, 89, 20, 6A, 01, E8, 80, 97, F0, FF, E8, 7F, DA, FF, FF, A1, CC, D9, 4F, 00, 50, 68, 30, DA, 4F, 00, A1, 14, 3E, 50, 00, 8B, 00, E8, 28, C2, F7, FF, E8, D3, DA, FF, FF, 33, C0, 5A, 59, 59, 64, 89, 10, EB, 19, E9, 5C, 46, F0, FF...
 
[+]

Entropy:
6.4146

Developed / compiled with:
Microsoft Visual C++

Code size:
1018 KB (1,042,432 bytes)

Remove update.tmp - Powered by Reason Core Security