pluginupdate1.92.exe

The executable pluginupdate1.92.exe has been detected as malware by 26 anti-virus scanners. This is a setup program which is used to install the application. This is a trojan Bot that uses IRC to communicate with a comand and control network. The Trojan drops other malicious software and opens a backdoor on the infected computer and will run automatically on each boot. The file has been seen being downloaded from goo.gl.
MD5:
5e744657413b245f4096d23112c5ade2

SHA-1:
de899ce9ca2b3cfdccfd460aaebccef72fc55ef9

SHA-256:
327e8522bda67e18179e70b19b473dc6b22edc27a6efb0fcd739295c8abc1602

Scanner detections:
26 / 68

Status:
Malware

Explanation:
Part of a backdoor IRC bot network.

Analysis date:
4/26/2024 2:59:07 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.jzWavvDYbRlin
640

Agnitum Outpost
Trojan.Themida
7.1.1

Avira AntiVirus
TR/Crypt.TPM.Gen
7.11.217.176

avast!
Win32:Malware-gen
2014.9-150506

AVG
Generic11_c
2016.0.3118

Baidu Antivirus
Trojan.Win32.Themida
4.0.3.1556

Bitdefender
Gen:Trojan.Heur.jzWavvDYbRlin
1.0.20.630

Bkav FE
W32.HfsAutoB
1.3.0.6379

Comodo Security
UnclassifiedMalware
21434

Emsisoft Anti-Malware
Gen:Trojan.Heur.jzWavvDYbRlin
8.15.05.06.07

ESET NOD32
Win32/Packed.Themida.ABF (variant)
9.11328

Fortinet FortiGate
PossibleThreat
5/6/2015

F-Secure
Gen:Trojan.Heur.jzWavvDYbRlin
11.2015-06-05_4

G Data
Gen:Trojan.Heur.jzWavvDYbRlin
15.5.25

K7 AntiVirus
Trojan
13.201.15274

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.2084

McAfee
Artemis!5E744657413B
5600.6774

MicroWorld eScan
Gen:Trojan.Heur.jzWavvDYbRlin
16.0.0.378

NANO AntiVirus
Trojan.Win32.TPM.dfdyzo
0.30.0.296

Norman
Troj_Generic.VUCQK
11.20150506

Rising Antivirus
PE:Packer.Win32.Mian007.a!1074235325
23.00.65.15504

Sophos
Mal/EncPk-DW
4.98

Trend Micro House Call
TROJ_GEN.R0C2C0EIR14
7.2.126

Trend Micro
TROJ_GEN.R0C2C0EIR14
10.465.06

VIPRE Antivirus
Backdoor.Win32.Ircbot.gen
38478

Zillya! Antivirus
Trojan.Packed.Win32.44035
2.0.0.2101

File size:
1.1 MB (1,197,568 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\pluginupdate1.92.exe

File PE Metadata
Compilation timestamp:
9/14/2014 7:28:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.23

CTPH (ssdeep):
24576:EiOuIbZ91umZSb7v24j8v9b/ahSNj9E0XuPTQYAaOcIygxjtxXE:yx9USUAFVjlX4JHyxo

Entry address:
0x2CC000

Entry point:
81, EC, 04, 00, 00, 00, 89, 14, 24, 89, 34, 24, 53, 89, 04, 24, 83, EC, 04, 89, 04, 24, 89, 1C, 24, E8, 01, 00, 00, 00, CC, FF, 34, 24, 58, 81, C4, 04, 00, 00, 00, 68, 17, 4F, 00, 00, 89, 2C, 24, 89, C5, 89, EB, 5D, 55, BD, FF, FF, FF, FF, 29, E8, 5D, 81, EC, 04, 00, 00, 00, 89, 0C, 24, B9, 00, B0, 11, 00, 29, C8, 59, 2D, 1F, 00, D6, 08, 05, 00, 00, D6, 08, 80, 3B, CC, 0F, 85, 63, 00, 00, 00, 51, B1, D8, C6, 03, D8, 28, 0B, 8B, 0C, 24, 81, C4, 04, 00, 00, 00, 51, 68, 09, 38, 7F, 67, 59, 81, E1, 6B, 15, 80...
 
[+]

Code size:
18.5 KB (18,944 bytes)

The file pluginupdate1.92.exe has been seen being distributed by the following URL.

Remove pluginupdate1.92.exe - Powered by Reason Core Security