updates.exe

The executable updates.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Updates’. While running, it connects to the Internet address 210.151.74.137.fr.axspace.com on port 80 using the HTTP protocol.
MD5:
88f2fff5964ad55652b46af9aa38b884

SHA-1:
92d203ead1629b1e382a284130c7ebafa748819d

SHA-256:
990a0c6d242a056dfcebc5da4bf1b9cbc6a0332e557a8f98a50f8496a02e81b6

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
1/13/2025 4:08:48 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Trojan.Downloader.UP (M)
17.2.1.15

File size:
920 KB (942,080 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
4/23/2002 2:12:37 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0xE5A96

Entry point:
89, FF, 89, ED, 83, 3C, 24, FE, 89, C9, 77, FE, FC, 8D, 64, 24, CC, 60, 83, EC, DC, F6, D5, E8, 72, 96, FF, FF, 4B, 66, 4B, 75, FC, FC, B6, FD, 90, FF, 73, 3C, 59, 81, E9, FD, FF, FF, 7F, 92, 73, EA, 86, C4, 90, 90, 81, D9, E6, 13, 00, 00, BF, 23, 28, D2, 68, BE, 9E, 22, 9B, 65, 71, D4, 80, DC, 29, 40, FF, B4, 19, E4, 13, 00, 80, 83, C4, 04, 66, 81, 44, 24, FC, B0, BA, 75, BD, B2, F8, 42, 42, 68, 64, 01, 2C, AF, E8, 47, 96, FF, FF, 83, F2, F5, 89, 74, 24, 44, E8, 31, 95, FF, FF, E9, 61, 95, FF, FF, 00, 00...
 
[+]

Entropy:
7.5382

Code size:
36 KB (36,864 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Updates

Command:
C:\updates.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to static.153.167.76.144.clients.your-server.de  (144.76.167.153:80)

TCP (HTTP):
Connects to 93-89-224-9.fbs.com.tr  (93.89.224.9:80)

TCP (HTTP):
Connects to 210.151.74.137.fr.axspace.com  (137.74.151.210:80)

Remove updates.exe - Powered by Reason Core Security