upwork.exe

oDesk Corporation SPC

The executable upwork.exe has been detected as malware by 3 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Upwork’.
Publisher:
oDesk Corporation SPC  (signed and verified)

MD5:
00463c33ba1558178b5d25102d6e1cd3

SHA-1:
9d4b9d308ea014731b51afdf9662c4ae3aade8fc

SHA-256:
fe01ff8ef71cc40ac983b3059106b5e1762b53fca0174371ac1d31be4be7b467

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
11/18/2024 11:25:00 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.15.154

File size:
1.7 MB (1,746,855 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\upwork\upwork.exe

Digital Signature
Authority:
oDesk Corporation CA

Valid from:
3/18/2015 7:59:42 AM

Valid to:
1/1/2040 5:59:59 AM

Subject:
CN=oDesk Corporation SPC

Issuer:
CN=oDesk Corporation CA

Serial number:
A068FD1366552AAE477D9E015BF13429

File PE Metadata
Compilation timestamp:
7/26/2015 1:55:49 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0xDB3AF

Entry point:
E9, DF, B4, FE, FF, E9, 39, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 53, 57, 33, DB, 6A, 07, 33, C0, 59, 8D, 7D, E4, 89, 5D, E0, F3, AB, 39, 45, 10, 75, 15, E8, 40, FD, FF, FF, C7, 00, 16, 00, 00, 00, E8, 63, A5, FF, FF, 83, C8, FF, EB, 75, 8B, 45, 0C, 56, 8B, 75, 08, 85, C0, 74, 19, 85, F6, 75, 15, E8, 1C, FD, FF, FF, C7, 00, 16, 00, 00, 00, E8, 3F, A5, FF, FF, 83, C8, FF, EB, 50, B9, FF, FF, FF, 7F, 89, 4D, E4, 3B, C1, 77, 03, 89, 45, E4, 8D, 45, 14, 50, 53, FF, 75, 10, 8D, 45, E0, 50, C7, 45, EC, 42, 00, 00...
 
[+]

Entropy:
6.7130

Packer / compiler:
Xtreme-Protector v1.05

Code size:
1.1 MB (1,104,384 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Upwork

Command:
C:\Program Files\upwork\upwork.exe


Remove upwork.exe - Powered by Reason Core Security