mkvtoolnix-unicode-5.2.0-setup.exe

MKVToolNix

Moritz Bunkus

The executable mkvtoolnix-unicode-5.2.0-setup.exe, “MKVToolNix 5.2.0 [20111203-387]” has been detected as malware by 2 anti-virus scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from cfile229.uf.daum.net and multiple other hosts.
Publisher:
Moritz Bunkus

Product:
MKVToolNix

Description:
MKVToolNix 5.2.0 [20111203-387]

Version:
5.2.0 [20111203-387]

MD5:
497e1c67cf5f0bbf8c08c34a2030ec87

SHA-1:
8a91942af2d7c4f97588641fd834915904c6c9b9

SHA-256:
d31dd7e8c63e438e5e9e93dbdb7b1ae1473fcfae8aa733f266d40b8529f4b455

Scanner detections:
2 / 68

Status:
Malware

Explanation:
This is part of the Crossrider Internet browser extension framework which may modify the user's web browser settings including changing the home and search pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
6/17/2024 2:07:22 PM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Android.Exploit.PSN
8.14.04.01.08

Reason Heuristics
Threat.Win.Reputation.IMP
16.11.29.14

File size:
6.3 MB (6,632,419 bytes)

Product version:
5.2.0 [20111203-387]

Copyright:
Moritz Bunkus http://www.bunkus.org/videotools/mkvtoolnix/

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\mkvtoolnix-unicode-5.2.0-setup.exe

File PE Metadata
Compilation timestamp:
6/6/2010 4:06:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
98304:cTHUWu/OdYxSTmq9MkiJqOan1DjZhm/SgHY7OQCug7ky65Set1utlEII64KFMD0P:cL9u/OdhrWyxsQC2vGxbF4o

Entry address:
0x39B8

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, 7C, 01, 00, 00, E8, 9B, 46, 00, 00, 83, EC, 0C, 68, 01, 80, 00, 00, E8, 46, 43, 00, 00, 6A, 00, E8, AF, 46, 00, 00, A3, 88, DC, 49, 00, 6A, 08, E8, 76, 28, 00, 00, A3, 38, DD, 49, 00, 8D, 85, 90, FE, FF, FF, 6A, 00, 68, 60, 01, 00, 00, 50, 6A, 00, 68, A4, A2, 40, 00, E8, F4, 45, 00, 00, 83, EC, 0C, 68, A5, A2, 40, 00, 68, 68, DD, 49, 00, E8, 96, 2A, 00, 00, 83, C4, 18, E8, 02, 43, 00, 00, 52, 52, 50, 68, 00, C4, 55, 00, E8, 81, 2A, 00, 00, 57, 6A, 00, E8, 55, 42, 00, 00, 83...
 
[+]

Code size:
28.5 KB (29,184 bytes)

The file mkvtoolnix-unicode-5.2.0-setup.exe has been seen being distributed by the following 5 URLs.

http://cfile229.uf.daum.net/.../274B344C53197EF73407F6

http://mfiles.naver.net/9e0b8234221514a3896b0a3906e295e5441eed35/20120114_107_blogfile/.../mkvtoolnix-unicode-5.2.0-setup.exe

http://uukoon.tistory.com/.../cfile30.uf@264D364E56852AB60F7DA3.exe

Remove mkvtoolnix-unicode-5.2.0-setup.exe - Powered by Reason Core Security