9557981_stp.exe

Windows Media Component Setup Application

Microsoft Corporation

This is a self-extracting archive and installer. The file has been seen being downloaded from pf.dlvit.com and multiple other hosts.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Windows Media Component Setup Application

Version:
11.0.5721.5262

MD5:
69474bff35ef9aea2a567a930334f1b9

SHA-1:
7e13190ed4065dfd5737bb22f95ac8a69518a169

SHA-256:
0201aa2144afc65207627f5df4299624cb9461aff418369ea77f4b702ae12a3e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/26/2024 4:48:25 PM UTC  (today)

File size:
24.6 MB (25,769,600 bytes)

Product version:
11.0.5721.5262

Copyright:
(C) Microsoft Corporation. All rights reserved.

Original file name:
WEXTRACT.EXE

File type:
Executable application (Win32 EXE)

Language:
French (France)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\9557981_stp.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
1/20/2009 2:58:26 AM

Valid to:
3/20/2010 3:08:26 AM

Subject:
CN=Microsoft Corporation, OU=AOC, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
6101640F00000000000B

File PE Metadata
Compilation timestamp:
6/6/2000 10:43:56 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
393216:3a6iH1rW3G0kvf+EpzanF8YWl4MGKO53KGKVmCb+pomfXke5/IECsn9HNmR37Wh:2NuEp2nFcGMGP5tCbcdX32TsVNmZm

Entry address:
0x2891

Entry point:
55, 8B, EC, 83, EC, 44, 56, FF, 15, DC, 10, 00, 01, 8B, F0, 8A, 06, 3C, 22, 75, 14, 8A, 46, 01, 46, 84, C0, 74, 04, 3C, 22, 75, F4, 80, 3E, 22, 75, 0D, 46, EB, 0A, 3C, 20, 7E, 06, 46, 80, 3E, 20, 7F, FA, 8A, 06, 84, C0, 74, 07, 3C, 20, 7F, 03, 46, EB, F3, 83, 65, E8, 00, 8D, 45, BC, 50, FF, 15, D8, 10, 00, 01, F6, 45, E8, 01, 74, 06, 0F, B7, 45, EC, EB, 03, 6A, 0A, 58, 50, 56, 6A, 00, 6A, 00, FF, 15, 60, 11, 00, 01, 50, E8, 0E, 00, 00, 00, 8B, F0, 56, FF, 15, D0, 10, 00, 01, 8B, C6, 5E, C9, C3, 56, 33, F6...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
34 KB (34,816 bytes)

The file 9557981_stp.exe has been seen being distributed by the following 20 URLs.

http://pf.dlvit.com/s/2/.../26040-92346-windows-media-player.exe

http://dl1.jetelecharge.com/up/UfOtbUVKdg/.../windows-media-player-75-jetelecharge.exe

http://wwl.downlexx.com/?ic_user_id=775

http://d.telechargerfiles6.com/?data=BHyN3FtGpNw8zEgJk/arC4rVgyaJ0r5HvY/eH/1qRj7nHfTfSgQ48JO/9 v6W2PMu0oTPcImRogVE5biYkmzCd/LRxxKySfqVmlH/ZwMpACbBjEYoIQtJ4NdISLBY7c1UA2wBvinPbC/FMrvvuDMTY1E/jEWYLK 1bgiDJzIgft4TDa9 bNBgSIWlzVf26Gqah5LmL4j5PWGOdSvI wrVtChX6Gym4lh e3Y05uSrk4h3SQdaOGMOqexICWGa8BBBUzymb6BdkbDMMwCGQRyJPjFLQfyFHYHJf3aLYo2EKfD0QmN5Ai6NQjYeXFAhEcZBpKNKrk5B1/k0mKU8hnh6 I3QKsJDN3mVpm9kE/k841HVy3RQggwlBIzp7eopEAIpiIvJQAUbP0E2EOGbjFbST2CSJwbK7cigEBBd/UQPTVJr/u kp7DKrMm2dNjwKk5idL39v1MnlSfbvP2X/yT6BMlR7tvt6P Sdp8E6Uhl1cbd8q1n1EFqsWUaEbXwMVm3Y8Lru E RCiB5msKHQ9pWEUr2f1LsA04g513EBYXJk iCg314sAcrDIyX86oOHQjq/YwB7r2gXY/GvOvmHb1UQwFK2JtqPc&key=NNRyouvwIUeOPsjs0 wlK25rChOmN2m69yrY2Nmh29hyg6YJ1RZu09QTDZA4EKlH9RxCGMu6JpY6y/x9L3VyLZIOBjF5aBe1DqCGm1j aout3HnMqWD3YsmivgiRtdBmSwDjtk2pkazhY3s LJh/cWbuZ/9 /ugrJAvIu9wBRcSSGhGYGoofX11Uok5tVqaWUyYiUT4VHew5nAVLRDFTvFPaiAB7ZPU 6riWzCMLlCRfzUfSZEmqxquVE9hDC/.../rHs1 WBISBMJwfaVQ==&ic_us

http://www.toucharger.com/.../00f7ebcb.dl

http://www.lelogicielgratuit.com/.../0ad3f73a.dl

http://www.jetelecharge.com/.../telp.php?id=75

http://cdn.jdmtacrymfooecactowersigns.com/c?x=UhatvKpmOQ7TbPPUXjyWigLmu8tteOKwWhQLYi0usIg=&c=dt9DJohdhcOqFxHXCzuliidljWzV0wBfXfa2MbN9f4JTMfvfGLMID13AWgOBEqznGwi5MYDo1w7EuEvOvV01Sz7cRPv3zuvDBq2P3chN9HUCg4zlSW3sxM74iCH7 fcK6kJaaO/LI9nF4GKbfE4sfA==&fallback_url=http://res.setauls.com/.../wmp11-windowsxp-x86-FR-FR.exe

temp:wmp11-windowsxp-x86-FR-FR.exe