
Matching hash gives update.exe a second location—and Startup significance
A sandbox report places the analyzed executable’s exact content at a local `Start\update.exe` path, while a registry event sets the user’s Startup folder to that directory. Together they support a potential logon-persistence arrangement, but do not establish how the file arrived or whether it ran at logon.
A Windows executable appears in a sandbox report at %USERPROFILE%\AppData\Local\Start\update.exe, with exactly the same SHA-256 as the file submitted for analysis. A registry event associated with that sample records another important change: the user’s Startup folder is set to %USERPROFILE%\AppData\Local\Start. Why put the executable there? The folder’s role in the user’s configuration offers a more consequential explanation than its ordinary-looking name.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read