windows 9.exe

The application windows 9.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from sta.sh. While running, it connects to the Internet address server-54-230-199-86.lhr50.r.cloudfront.net on port 80 using the HTTP protocol.
MD5:
ac359d87bc0bfd41fb04ce9a0b4ae2f9

SHA-1:
c747358a8ab34e2be4d0742c8b78c4e5b53af345

SHA-256:
3904119e893bc2f6bbcca428354d1b4e92f8708d1f2b25a4b75318d6b0e195c4

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 1:11:31 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Dropper-gen [Drp]
2014.9-140422

Baidu Antivirus
Trojan.Win32.DownWare
4.0.3.14422

ESET NOD32
Win32/DownWare
8.9704

K7 AntiVirus
Trojan
13.176.11833

McAfee
Artemis!AC359D87BC0B
5600.7153

Norman
Malware.AJATU
11.20140422

Qihoo 360 Security
Win32/Trojan.Dropper.c9f
1.0.0.1015

Trend Micro House Call
TROJ_GEN.F47V0119
7.2.112

File size:
9.8 MB (10,327,792 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\windows 9.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:hTUD4WHXu8PsrPrBgYS85GlXLH6nI/1gAaf2LBxcCp3FaTmF4Sp:KDFHXHPsrPlgr8yLHfOP2LBxcM3Fa7Y

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file windows 9.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-199-86.lhr50.r.cloudfront.net  (54.230.199.86:80)

TCP (HTTP):
Connects to server-54-230-196-210.lhr50.r.cloudfront.net  (54.230.196.210:80)

Remove windows 9.exe - Powered by Reason Core Security