wrupdate104665140.exe

Webroot SecureAnywhere

Webroot Inc.

This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WRSVC’. The file has been seen being downloaded from www.laplink.com and multiple other hosts.
Publisher:
Webroot  (signed by Webroot Inc.)

Product:
Webroot SecureAnywhere

Version:
9.0.7.42

MD5:
ff238633fd0ed5c60779266ad78764af

SHA-1:
7111dd2f72a1111d3f86525fcfb8c4d83ab8c20c

SHA-256:
3c683f15bd7cc97aa99f79c7c68df3267ae61e4f88acfe72c0cff5343ec4077e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 3:24:30 PM UTC  (today)

File size:
823.6 KB (843,360 bytes)

Product version:
9.0.7.42

Copyright:
(c) Webroot 2006-2015

Original file name:
WRSA.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\wrupdate104665140.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/22/2013 6:00:00 PM

Valid to:
2/21/2016 5:59:59 PM

Subject:
CN=Webroot Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Webroot Inc., L=Broomfield, S=Colorado, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0F93940D35AB8B900B117F5574BA1090

File PE Metadata
Compilation timestamp:
12/14/2015 10:08:09 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:CSV1TAEOQ77H7a6itbv9mIHgCm8Qa+6EEE12YLl14DrjQRe6IOiy/vi4I3MCCi62:CSVFL7T7mM/bEq2z75Y/a4cMCCi658

Entry address:
0x248AC0

Entry point:
60, BE, 00, 50, 18, 01, 8D, BE, 00, C0, E7, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 1B, 69, 24, 00, 57, 83, C3, 04, 53, 68, B3, 3A, 0C, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Entropy:
7.9829  (probably packed)

Code size:
788 KB (806,912 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WRSVC

Command:
"C:\Program Files\webroot\wrsa.exe" -ul


The file wrupdate104665140.exe has been seen being distributed by the following 2 URLs.

Scan wrupdate104665140.exe - Powered by Reason Core Security