CitrixOnlinePluginWeb.exe

Citrix ICA Client

CITRIX SYSTEMS, INC

This is a setup program which is used to install the application. The file has been seen being downloaded from mon.forfait-informatique.com and multiple other hosts.
Publisher:
Citrix Systems, Inc.  (signed by CITRIX SYSTEMS, INC)

Product:
Citrix ICA Client

Description:
Citrix online plug-in web

Version:
11.2.0.31560

MD5:
f4aa8a73498387c63e543f62dad63b5f

SHA-1:
b67da5e350b2becb7a7f2a07d35e080d14137dfa

SHA-256:
99c757da63ebddedbb948104e2bf24cfa0329d7de86cb36ada5e7c1925411ad5

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/5/2024 2:35:09 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
17497

File size:
11.1 MB (11,605,360 bytes)

Product version:
11.2.0

Copyright:
Copyright (c) 1990-2009 Citrix Systems, Inc.

Original file name:
CitrixOnlinePluginWeb.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\citrixonlinepluginweb.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/5/2009 7:00:00 PM

Valid to:
3/31/2010 7:59:59 PM

Subject:
CN="CITRIX SYSTEMS, INC", OU="CITRIX SYSTEMS, INC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="CITRIX SYSTEMS, INC", L=Fort Lauderdale, S=Florida, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
39C70944F2C31AB974E85B3388A34F39

File PE Metadata
Compilation timestamp:
9/12/2009 6:28:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
196608:FCvwFwCMBs4K5oe4EBwKsNYnxKSfQj+z+LKkuX7zx5rvJqbkggTteth722fnNAZ2:SwYvKSeDBwKsyxs+aRuLz3vJ4k1tteN7

Entry address:
0x253DC

Entry point:
E8, 9C, 72, 00, 00, E9, 17, FE, FF, FF, 8B, 44, 24, 04, 8B, D0, 66, 8B, 08, 40, 40, 66, 85, C9, 75, F6, 66, 8B, 4C, 24, 08, 48, 48, 3B, C2, 74, 05, 66, 39, 08, 75, F5, 66, 8B, 10, 66, 2B, D1, 66, F7, DA, 1B, D2, F7, D2, 23, C2, C3, 6A, 0C, 68, 38, 12, 46, 00, E8, 4E, 12, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, 08, B2, 46, 00, 03, 75, 43, 6A, 04, E8, 66, 74, 00, 00, 59, 83, 65, FC, 00, 56, E8, 77, 75, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, 93, 75, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF...
 
[+]

Entropy:
7.9874  (probably packed)

Code size:
328 KB (335,872 bytes)

The file CitrixOnlinePluginWeb.exe has been seen being distributed by the following 50 URLs.

https://mon.forfait-informatique.com/Citrix/AccessPlatform/clients_common/.../CitrixOnlinePluginWeb.exe

http://10.225.207.203/Citrix/Telefonica/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

https://matrix.bluefingroup.co.uk/CitrixSessionInit/.../CitrixOnlinePluginWeb.exe#Version=11.2.0.31560

https://access.alameda.courts.ca.gov/courts/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

http://188.117.105.91/Manar/App/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

http://citrix.kofax.com/Citrix/Xenapp/Clients/.../CitrixOnlinePluginWeb.exe

http://web1.usw.salvationarmy.org/CitrixOnlinePluginWeb11-2.exe

https://cag.ssib.es/Explicit/Clients_common/.../CitrixOnlinePluginWeb.exe

https://cc4anywhere.rokeby.newham.sch.uk/Citrix/CAG/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

http://citrix.duratex.com.br/Citrix/XenApp/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

https://emea-login.gs.com/LoginGS/Content/Citrix/.../CitrixOnlinePluginWeb.exe

https://rgwi.royalgreenland.com/Citrix/XenApp/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

http://bureau.ordremk.fr/MesServices/.../CitrixOnlinePluginWeb.exe

https://ext.synopsys.com/ext/Clients_common/Windows1/.../CitrixOnlinePluginWeb.exe

https://ext.naef.ch/Citrix/XenApp/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

http://xenapp.spiraxmexico.com/Citrix/XenApp/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

https://mis328.pti.com.tw/Citrix/XenApp/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

https://access.osumc.edu/Citrix/AGEE/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

https://www.tabwareonline.com/.../CitrixOnlinePluginWeb_v11p2.exe

http://www.zorgpartners.nl/.../CitrixOnlinePluginWebV11.2.exe

http://172.16.1.9/Citrix/XenApp1/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

https://netfusion.arcadiagroup.ltd.uk/Citrix/Netfusion/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

http://10.225.162.138/Telefonica/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

https://login.gs.com/LoginGS/Content/Citrix/.../CitrixOnlinePluginWeb.exe

https://41.33.200.226/.../CitrixOnlinePluginWeb.exe

http://xenapp.gzapata.com/Citrix/XenApp/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

https://hshs-ag.hshs.org/cvpn/aHR0cDovL2NhZ3dpLTAxLmhzaHMubG9jYWw/Citrix/XenApp/.../CitrixOnlinePluginWeb.exe

https://oce.ps-msite.com/Citrix/oce/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

http://mf.cn.eland.com/Citrix/AccessPlatform1/Clients_common/.../CitrixOnlinePluginWeb.exe

https://cloud.usi.com.tw/Citrix/XenAppWeb/Clients_common/Windows/.../CitrixOnlinePluginWeb.exe

Latest 30 of 214 download URLs