updater.exe

Arne Koenig

The application updater.exe by Arne Koenig has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘GIMP Updater’. This file is typically installed with the program GIMP Updater by GIMP. While running, it connects to the Internet address s01.webspace24.de on port 80 using the HTTP protocol.
Publisher:
Arne Koenig  (signed and verified)

MD5:
006a5c9e3134395b004cabb7326a9380

SHA-1:
ed562b5ffc183caba9c044ce1ef87ec1eb30448a

SHA-256:
3214ac16031c234f48149b48982a71b37487fef964669b7c18fcb85792b0aa0a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 9:40:41 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.19.3

File size:
222.5 KB (227,848 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\gimp updater\updater.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
8/17/2015 12:22:40 PM

Valid to:
11/4/2018 11:29:51 AM

Subject:
CN=Arne Koenig, O=Arne Koenig, L=Verden, S=Niedersachsen, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112156400F30E98EC0755AF2B124F4872F61

File PE Metadata
Compilation timestamp:
7/25/2016 2:55:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x310F

Entry point:
81, EC, 84, 01, 00, 00, 53, 56, 57, 33, DB, 68, 01, 80, 00, 00, 89, 5C, 24, 18, C7, 44, 24, 10, 98, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, A8, 70, 40, 00, FF, 15, A4, 70, 40, 00, 66, 3D, 06, 00, 74, 11, 53, E8, 7C, 2F, 00, 00, 3B, C3, 74, 07, 68, 00, 0C, 00, 00, FF, D0, BE, 98, 72, 40, 00, 56, E8, F8, 2E, 00, 00, 56, FF, 15, A0, 70, 40, 00, 8D, 74, 06, 01, 38, 1E, 75, EB, 55, 6A, 09, E8, 4F, 2F, 00, 00, 6A, 07, E8, 48, 2F, 00, 00, A3, 04, E4, 42, 00, FF, 15, 44, 70, 40, 00, 53, FF, 15, 88...
 
[+]

Code size:
24 KB (24,576 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
GIMP Updater

Command:
C:\users\{user}\appdata\roaming\gimp updater\updater.exe


The file updater.exe has been discovered within the following program.

GIMP Updater  by GIMP
About 9% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to s01.webspace24.de  (78.46.96.66:80)

Remove updater.exe - Powered by Reason Core Security