updates.exe

The executable updates.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Updates’. While running, it connects to the Internet address hv8svg015.neubox.net on port 80 using the HTTP protocol.
MD5:
e5cc9d4116229d7b1672eed4eec8b626

SHA-1:
f5fbd84f0063bdb023e8b9e1090f6aeeffca3e04

SHA-256:
aa66053c76accdf2a45b0afa9569ec1280351a64dfb3643e4a758c7b42f7dde3

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
1/13/2025 4:29:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Trojan.Downloader.UP (M)
17.2.26.22

File size:
152 KB (155,648 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
11/18/2000 11:35:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x17EC

Entry point:
60, 24, 96, 57, 53, 8D, 0D, 6E, A0, 30, 9D, 39, CA, 0F, BF, F6, 3D, 9D, 26, 00, 00, 72, 02, 87, F3, 76, 0C, 69, FD, 8F, 7B, 6E, BD, C7, C0, 57, 0F, B0, F0, 0C, EF, 83, E2, 00, 3D, ED, A9, 4C, B1, 80, D0, A8, 32, DA, 0B, D2, 35, 76, B1, 37, 81, FE, C7, FE, CD, 88, DF, EB, 05, 00, CB, 46, 32, C9, 83, E7, 00, 69, F2, A0, 19, 7B, 28, 8B, EF, 89, D5, F3, 8B, DA, EB, 04, 8B, D0, 86, CD, 8D, 35, 63, 00, E8, 3C, 03, D5, 6A, 00, 5D, FF, C1, 32, D8, 81, ED, B4, 05, 00, 00, 42, 3D, FB, 32, 49, 56, 81, F5, 75, 08, 00...
 
[+]

Entropy:
6.8723

Code size:
36 KB (36,864 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Updates

Command:
C:\updates.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to hv8svg015.neubox.net  (65.99.252.96:80)

TCP (HTTP):
Connects to whw0071.whservidor.com  (200.98.255.192:80)

TCP (HTTP):
Connects to mailserver40.mylittledatacenter.com  (144.76.167.153:80)

TCP (HTTP):

TCP (HTTP):
Connects to 93-89-224-9.fbs.com.tr  (93.89.224.9:80)

TCP (HTTP):
Connects to 210.151.74.137.fr.axspace.com  (137.74.151.210:80)

TCP (HTTP):
Connects to 19.187.196.5.fr.axspace.com  (5.196.187.19:80)

Remove updates.exe - Powered by Reason Core Security