vlc-1.0.3-win32.exe

The executable vlc-1.0.3-win32.exe has been detected as malware by 2 anti-virus scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from software.oldversion.com and multiple other hosts.
MD5:
5c707790262c303361d05a144c8089f4

SHA-1:
ff8e2092d9126b041f6ab0da85779058157a48c9

SHA-256:
5d9710dcd8ac18329cfcb23a7bea0e046e1da4483210286a81c82942f810019c

Scanner detections:
2 / 68

Status:
Malware

Explanation:
This is part of the Crossrider Internet browser extension framework which may modify the user's web browser settings including changing the home and search pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/27/2024 12:34:58 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.11.29.12

ViRobot
Trojan.Win32.A.Clicker.18030130
2011.4.7.4223

File size:
17.2 MB (18,030,130 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Common path:
C:\users\{user}\downloads\vlc-1.0.3-win32.exe

File PE Metadata
Compilation timestamp:
8/19/2009 5:25:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
393216:O8Jpo7PTmH5OonLHuEr5UftVbekaa+lk+cfO+X3EtQB:jnoXmHvLHYbWl36O+E6B

Entry address:
0x4044

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, E8, 1B, 57, 00, 00, C7, 04, 24, 01, 80, 00, 00, E8, 7F, 50, 00, 00, 56, C7, 04, 24, 00, 00, 00, 00, E8, 52, 57, 00, 00, A3, 88, 5C, 42, 00, 53, C7, 04, 24, 08, 00, 00, 00, E8, 26, 32, 00, 00, A3, 38, 5D, 42, 00, 8D, 85, 84, FE, FF, FF, 51, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A4, B2, 40, 00, E8, EC, 55, 00, 00, 83, EC, 14, C7, 44, 24, 04, A5, B2, 40, 00, C7, 04, 24, 68, 5D...
 
[+]

Entropy:
7.9994  (probably packed)

Code size:
34.5 KB (35,328 bytes)

The file vlc-1.0.3-win32.exe has been seen being distributed by the following 22 URLs.

http://software.oldversion.com/download.php?f=YTo1OntzOjQ6InRpbWUiO2k6MTQ3NzIzMjg4NTtzOjI6ImlkIjtpOjQyNTQ7czo0OiJmaWxlIjtzOjE5OiJ2bGMtMS4wLjMtd2luMzIuZXhlIjtzOjM6InVybCI7czo1NjoiaHR0cDovL3d3dy5vbGR2ZXJzaW9uLmNvbS93aW5kb3dzL3ZsYy1tZWRpYS1wbGF5ZXItMS0wLTMiO3M6NDoicGFzcyI7czozMjoiMGI3NjE1NWY1MjkwMjU3M2MxNjg0YmE2OTVmNmIxODUiO30=

http://piotrkosoft.net/pub/mirrors/videolan/vlc/1.0.3/.../vlc-1.0.3-win32.exe

http://s10140.chomikuj.pl/File.aspx?e=IsWOMbWi8TmVNoOOEmd3bc-7yonSo92CW-z0l9Cv7NY-TiDyxKP9DmWsuBwINCWvXcPXDgts963obQbApyJ6UQdOd4CKzGIbUTSrPRDbgdRGiyhjW3YPPZW-iKuJd0BwgmBTsZ1F_tnj1QUjYLOqXfDczlbdAiV02Y76jzfmngk&pv=2

http://ftp.rezopole.net/vlc/vlc/1.0.3/.../vlc-1.0.3-win32.exe

ftp://10.141.13.8/d/.../vlc-1.0.3-win32.exe

http://videolan.ip-connect.vn.ua/vlc/1.0.3/.../vlc-1.0.3-win32.exe

http://fs5.filehippo.com/5709/.../vlc-1.0.3-win32.exe

temp:vlc-1.0.3-win32.exe

http://filehippo.com/es/download/file/.../

about:internet

Remove vlc-1.0.3-win32.exe - Powered by Reason Core Security