updates.exe

The executable updates.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Updates’. While running, it connects to the Internet address s10.zenbox.pl on port 80 using the HTTP protocol.
MD5:
45c0b7449da09df7a169772b9e4ac572

SHA-1:
36ba5e05521bd6011fb3b66597267f4338da32c8

SHA-256:
690f92d1b708a0ef702d8a92d80d9eb6b7fad7997b3905a69dfcbf0e40834297

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/27/2024 7:51:12 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Trojan.Downloader.UP (M)
17.3.2.11

File size:
148 KB (151,552 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
1/24/2011 4:29:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x17EC

Entry point:
77, 0E, C7, C6, 69, D3, 7A, 65, 02, CB, 81, DF, B6, A4, 08, 70, 4A, C6, C7, BA, F2, 8B, EA, 2C, 9A, 72, 08, 69, D8, 6C, DA, EB, B4, 86, FC, 8D, 1D, 2A, FA, 3F, 85, 47, E8, 00, 00, 00, 00, 5A, 76, 01, F3, 8B, F7, 0F, B7, CA, FF, CE, 2A, E0, 89, F1, 19, F9, 0F, B7, C7, 0F, AF, D8, 3B, EA, 8B, CA, F6, C6, CA, 81, E0, D4, 0F, 23, 65, 84, E3, F6, C6, 45, 68, 3D, DD, 91, 00, 87, DF, 86, CF, 84, E8, EB, 06, 86, C5, 30, D0, FF, CE, EB, 08, 69, EA, 02, 09, 07, 25, 87, EB, 8B, D9, FE, C5, 69, F9, FF, 97, 5B, CE, 0D...
 
[+]

Entropy:
6.8190

Code size:
36 KB (36,864 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Updates

Command:
C:\updates.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to unknown.prolexic.com  (72.52.4.120:80)

TCP (HTTP):
Connects to s10.zenbox.pl  (185.23.21.220:80)

Remove updates.exe - Powered by Reason Core Security