install_autowebcam.exe

The executable install_autowebcam.exe has been detected as malware by 8 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from www.intramessenger.com.
MD5:
291c02625eb40627ffa606176f6bba1e

SHA-1:
7b27f1440b4e081f2949d7bb0774af985243bf89

SHA-256:
21b29b62e14ab2f48072eccbb00b3cd3dfccec9fa38e2d57b7cdeced87aaadfa

Scanner detections:
8 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/16/2024 3:42:23 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160518-2

AVG
Win32/Sality
2015.0.4604

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
16.07.02

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.225.81.0

Norman
Win32.Sality.3
22.05.2016 07:18:28

File size:
2.1 MB (2,253,361 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\install_autowebcam.exe

File PE Metadata
Compilation timestamp:
10/6/1999 12:33:39 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
3.0

CTPH (ssdeep):
49152:YfPJBTJqa+jTfgLw3gPo1GC65p1YKbmRAsjek1Z/JA:QPZfg083fGz1tbmRT/g

Entry address:
0x1020

Entry point:
60, 8A, F4, 08, C6, 0F, AF, FA, B9, 20, 7A, 90, FA, 33, F2, 73, 02, B4, 1D, 43, 80, CD, 2C, 8A, D8, F2, 88, F8, 69, C8, 5F, 84, 56, 79, E8, 29, 00, 00, 00, 05, F3, 99, A0, C2, 0F, BE, FB, BD, AE, E5, 84, A7, 69, FB, A3, 67, D1, 66, 0F, AF, F8, 8D, 35, 16, 90, 3A, F3, 2B, DB, 77, 09, 38, E9, F3, F7, C6, 3D, 7F, 0C, F2, EB, 06, C7, C7, 38, D4, 7D, F5, 70, 03, 0F, AF, CD, 08, E6, FE, C4, 12, E4, EB, 05, C6, C4, BE, FF, C5, FE, C4, 33, E9, 87, CA, 8B, FD, B1, B5, 10, CA, 1D, 6A, 5D, C3, 88, 8A, C9, 89, E9, 2B...
 
[+]

Code size:
2.5 KB (2,560 bytes)

The file install_autowebcam.exe has been seen being distributed by the following URL.

Remove install_autowebcam.exe - Powered by Reason Core Security