video_player_upgrade.exe

The executable video_player_upgrade.exe has been detected as malware by 34 anti-virus scanners. This is a setup program which is used to install the application. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server. The file has been seen being downloaded from chaosium.com and multiple other hosts.
MD5:
09b9623826f9bcb733a2ad35ba2658bb

SHA-1:
c275dab361e4364f7afb1bf9610cf2e4312a0ba4

SHA-256:
889275c20a4e3debe02c9ab87b0b231b1e1a927270581a43a5bf812b02d61965

Scanner detections:
34 / 68

Status:
Malware

Analysis date:
4/25/2024 2:56:11 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Inject.APV
357

Agnitum Outpost
Trojan.Injector
7.1.1

AhnLab V3 Security
Spyware/Win32.Zbot
2015.03.11

Avira AntiVirus
TR/Crypt.XPACK.Gen7
7.11.215.236

avast!
Win32:Zbot-SNH [Trj]
2014.9-160212

AVG
Zbot
2017.0.2835

Baidu Antivirus
Trojan.Win32.Injector
4.0.3.16212

Bitdefender
Trojan.Inject.APV
1.0.20.215

Comodo Security
TrojWare.Win32.Injector.AWLZ
21366

Dr.Web
Trojan.PWS.Panda.5676
9.0.1.043

Emsisoft Anti-Malware
Trojan.Inject.APV
8.16.02.12.08

ESET NOD32
Win32/Injector.AWOF (variant)
10.11300

Fortinet FortiGate
W32/Kryptik.WIF!tr
2/12/2016

F-Secure
Trojan.Inject.APV
11.2016-12-02_6

G Data
Trojan.Inject.APV
16.2.25

IKARUS anti.virus
Virus.Win32.CeeInject
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.200.15223

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.671

Malwarebytes
Trojan.Inject.ED
v2016.02.12.08

McAfee
Dowloader-FEX
5600.6491

Microsoft Security Essentials
VirTool:Win32/CeeInject
1.1.11400.0

MicroWorld eScan
Trojan.Inject.APV
17.0.0.129

NANO AntiVirus
Trojan.Win32.Zbot.cswmcn
0.30.0.296

Norman
Troj_Generic.SKVCK
11.20160212

nProtect
Trojan.Inject.APV
15.03.10.01

Panda Antivirus
Trj/Genetic.gen
16.02.12.08

Qihoo 360 Security
Win32/Backdoor.117
1.0.0.1015

Quick Heal
Trojan.CeeInject.r6
2.16.14.00

Rising Antivirus
PE:Trojan.Injector!1.9F7C
23.00.65.16210

Sophos
Troj/Agent-AFZL
4.98

Trend Micro House Call
TROJ_SPNR.06B414
7.2.43

Trend Micro
TROJ_SPNR.06B414
10.465.12

Vba32 AntiVirus
Trojan.Inject
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Fareit.if
38312

File size:
162.8 KB (166,713 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\video_player_upgrade.exe

File PE Metadata
Compilation timestamp:
1/20/2014 8:42:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
1.0

CTPH (ssdeep):
3072:2YpMeFhBETUhaOwqVmFwJGyTe4/u9+ZBu2lLmAe1Y:XpM4hWfSmLyT7/uOZlaLu

Entry address:
0x25B0

Entry point:
55, 8B, EC, 6A, FF, E9, 36, F2, FF, FF, 68, C0, 27, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, C4, 98, 53, 56, 57, 89, 65, E8, C7, 45, FC, 00, 00, 00, 00, 6A, 02, FF, 15, D0, 57, 40, 00, 83, C4, 04, C7, 05, FC, 4A, 40, 00, FF, FF, FF, FF, C7, 05, 00, 4B, 40, 00, FF, FF, FF, FF, FF, 15, CC, 57, 40, 00, 8B, 0D, 90, 4A, 40, 00, 89, 08, FF, 15, C8, 57, 40, 00, 8B, 15, EC, 4A, 40, 00, 89, 10, A1, C4, 57, 40, 00, 8B, 08, 89, 0D, F8, 4A, 40, 00, E8, 86, 01, 00, 00, A1, A0, 40, 40, 00, 85...
 
[+]

Entropy:
7.6659

Developed / compiled with:
Microsoft Visual C++

Code size:
6.5 KB (6,656 bytes)

The file video_player_upgrade.exe has been seen being distributed by the following 2 URLs.

Remove video_player_upgrade.exe - Powered by Reason Core Security