wuu_utiltop.exe

POSTMEDIA Co.,Ltd

The application wuu_utiltop.exe by POSTMEDIA Co.,Ltd has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from utiltop.com and multiple other hosts.
Publisher:
POSTMEDIA Co.,Ltd  (signed and verified)

MD5:
886d8f56bc1819504d82d15457b2f8b8

SHA-1:
ec8d6656606445d21befa9ce0cd0806cf73b6120

SHA-256:
79dde3dcbab983ffc4efae3af12b84693fec72ff4774677cf22cc56d1f77b08a

Scanner detections:
11 / 68

Status:
Adware

Analysis date:
12/26/2024 6:17:08 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Rkit/Agent.1124560
7.11.121.182

avast!
Win32:Rootkit-gen [Rtk]
2014.9-140128

Bkav FE
W32.Clod2b6.Trojan
1.3.0.4613

Dr.Web
Trojan.Adkor.45
9.0.1.028

Emsisoft Anti-Malware
Gen:Variant.Zusy.76984
8.14.01.28.07

IKARUS anti.virus
Win32.Rootkit
t3scan.2.2.29

Malwarebytes
Adware.KorAd
v2014.01.28.07

McAfee
Artemis!886D8F56BC18
5600.7237

nProtect
Adware/W32.Agent1.1124560
13.12.23.01

Reason Heuristics
PUP.POSTMEDIACoLtd.L
14.12.11.23

Trend Micro House Call
TROJ_GE.B688692C
7.2.28

File size:
1.1 MB (1,124,560 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\wuu_utiltop.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
10/16/2012 9:00:00 AM

Valid to:
1/16/2015 8:59:59 AM

Subject:
CN="POSTMEDIA Co.,Ltd", OU=Dev Team, O="POSTMEDIA Co.,Ltd", L=Nam-gu, S=Busan, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1A0F99EE00FE980DD6E95535BDC8BB31

File PE Metadata
Compilation timestamp:
12/6/2009 7:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:1kvGyFJLwQwv77DwzpMRK4FGS3CtWutY6LUSCQbJd5A8lbJd5A8z:mVDwcVMR1FGWCtrfoBQbSwbSc

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9849

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file wuu_utiltop.exe has been seen being distributed by the following 2 URLs.

Remove wuu_utiltop.exe - Powered by Reason Core Security