update32.exe

JProof LLC

The application update32.exe by JProof has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address ip217.ip-178-32-196.eu on port 8005.
Publisher:
JProof LLC  (signed and verified)

MD5:
c278e29da04a66e497a9daeb601f94d7

SHA-1:
2051e823e4733a904e31ae4406bad64136f54ef4

SHA-256:
95a38033e8a1dddfaca80c9a9ad6dbcdf8e41a05eb5285a4bce3b0262c862434

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 12:20:16 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.EpicScale (M)
17.3.3.11

File size:
3.3 MB (3,477,096 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\system\adobe\update32.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
10/5/2014 3:00:00 AM

Valid to:
10/11/2017 3:00:00 PM

Subject:
CN=JProof LLC, O=JProof LLC, L=Washington, S=New Jersey, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
010A6723CC9454568F41F9221A61B586

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.24

Entry address:
0x14E0

Entry point:
83, EC, 0C, C7, 05, 10, 1E, 75, 00, 00, 00, 00, 00, E8, 1E, C5, 1D, 00, 83, C4, 0C, E9, 86, FC, FF, FF, 90, 90, 90, 90, 90, 90, 55, 89, E5, 56, 53, 83, EC, 10, 8B, 1D, 50, 44, 75, 00, C7, 04, 24, 00, 60, 6A, 00, FF, D3, 89, C6, 83, EC, 04, B8, E0, 27, 5E, 00, 85, F6, 74, 29, C7, 04, 24, 00, 60, 6A, 00, FF, 15, 98, 44, 75, 00, 83, EC, 04, A3, B4, 2B, 75, 00, C7, 44, 24, 04, 13, 60, 6A, 00, 89, 34, 24, FF, 15, 58, 44, 75, 00, 83, EC, 08, 85, C0, 74, 11, C7, 44, 24, 04, 20, 00, 75, 00, C7, 04, 24, C8, 20, 6F...
 
[+]

Entropy:
6.4439

Code size:
2.6 MB (2,739,712 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP:
Connects to ip217.ip-178-32-196.eu  (178.32.196.217:8005)

TCP:
Connects to ip106.ip-79-137-57.eu  (79.137.57.106:8005)

TCP:
Connects to ip20.ip-144-217-101.net  (144.217.101.20:8005)

TCP:
Connects to ip241.ip-144-217-61.net  (144.217.61.241:8005)

Remove update32.exe - Powered by Reason Core Security