APTMembers
APT

Matching hash gives update.exe a second location—and Startup significance

A sandbox report places the analyzed executable’s exact content at a local `Start\update.exe` path, while a registry event sets the user’s Startup folder to that directory. Together they support a potential logon-persistence arrangement, but do not establish how the file arrived or whether it ran at logon.

Oct 6, 2026, 23:14 (UTC+9)Last seenOct 6, 2026Severity77ByCTX TeamActorSalty SpiderKuKuIOC25MITRE23RegionsAUITTR

A Windows executable appears in a sandbox report at %USERPROFILE%\AppData\Local\Start\update.exe, with exactly the same SHA-256 as the file submitted for analysis. A registry event associated with that sample records another important change: the user’s Startup folder is set to %USERPROFILE%\AppData\Local\Start. Why put the executable there? The folder’s role in the user’s configuration offers a more consequential explanation than its ordinary-looking name.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence