video_player_upgrade.exe

The executable video_player_upgrade.exe has been detected as malware by 36 anti-virus scanners. This is a setup program which is used to install the application. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server. The file has been seen being downloaded from chaosium.com and multiple other hosts.
MD5:
1bc4c19a10d9a9e512ed14f6e19ab120

SHA-1:
1900503b54547986bc377a05a114c2a0dbc93984

SHA-256:
62242a9b8e586c1f3565fc6d392580de9382881188bec0d0289313e064838dac

Scanner detections:
36 / 68

Status:
Malware

Analysis date:
4/6/2025 6:55:07 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Inject.APV
359

AegisLab AV Signature
Troj.W32.Generic!c
2.1.4+

Agnitum Outpost
Trojan.Inject
7.1.1

AhnLab V3 Security
Win-Trojan/Zbot.77625
2016.02.06

Avira AntiVirus
TR/Crypt.XPACK.Gen7
8.3.2.4

avast!
Win32:Crypt-QNU [Trj]
2014.9-160211

AVG
Generic35
2017.0.2837

Baidu Antivirus
Trojan.Win32.Injector
4.0.3.16211

Bitdefender
Trojan.Inject.APV
1.0.20.210

Comodo Security
TrojWare.Win32.Injector.AWLZ
24095

Dr.Web
Trojan.PWS.Panda.5676
9.0.1.042

Emsisoft Anti-Malware
Trojan.Inject.APV
8.16.02.11.09

ESET NOD32
Win32/Injector.AWOF (variant)
10.12982

Fortinet FortiGate
W32/Kryptik.WIF!tr
2/11/2016

F-Secure
Trojan.Inject.APV
11.2016-11-02_5

G Data
Trojan.Inject.APV
16.2.25

IKARUS anti.virus
Virus.Win32.CeeInject
t3scan.2.0.6.0

K7 AntiVirus
Trojan
13.213.18657

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.678

Malwarebytes
Trojan.Injector.ED
v2016.02.11.09

McAfee
Dowloader-FEX
5600.6493

Microsoft Security Essentials
VirTool:Win32/CeeInject
1.1.12400.0

MicroWorld eScan
Trojan.Inject.APV
17.0.0.126

NANO AntiVirus
Trojan.Win32.Androm.csxwfj
1.0.14.5798

nProtect
Trojan.Inject.APV
16.02.05.01

Panda Antivirus
Trj/CI.A
16.02.11.09

Qihoo 360 Security
HEUR/Malware.QVM19.Gen
1.0.0.1120

Quick Heal
VirTool.CeeInject.S4
2.16.14.00

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.16209

Sophos
Troj/Agent-AFZL
4.98

Trend Micro House Call
TROJ_SPNR.06B414
7.2.42

Trend Micro
TROJ_SPNR.06B414
10.465.11

Vba32 AntiVirus
Trojan.Inject
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Fareit.if
46992

ViRobot
Trojan.Win32.S.Zbot.165689[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Inject.Win32.69066
2.0.0.2647

File size:
161.8 KB (165,689 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\video_player_upgrade.exe

File PE Metadata
Compilation timestamp:
1/20/2014 7:42:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
1.0

CTPH (ssdeep):
3072:DYA6e1LFxv3EWlJknDn46IMvVKkRHAknVvzX4+6zIgMUy6AWfkUX:sA6o3EWlJM461tbppBwIg06dX

Entry address:
0x25B0

Entry point:
55, 8B, EC, 6A, FF, E9, 36, F2, FF, FF, 68, C0, 27, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, C4, 98, 53, 56, 57, 89, 65, E8, C7, 45, FC, 00, 00, 00, 00, 6A, 02, FF, 15, D0, 57, 40, 00, 83, C4, 04, C7, 05, FC, 4A, 40, 00, FF, FF, FF, FF, C7, 05, 00, 4B, 40, 00, FF, FF, FF, FF, FF, 15, CC, 57, 40, 00, 8B, 0D, 90, 4A, 40, 00, 89, 08, FF, 15, C8, 57, 40, 00, 8B, 15, EC, 4A, 40, 00, 89, 10, A1, C4, 57, 40, 00, 8B, 08, 89, 0D, F8, 4A, 40, 00, E8, 86, 01, 00, 00, A1, A0, 40, 40, 00, 85...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
6.5 KB (6,656 bytes)

The file video_player_upgrade.exe has been seen being distributed by the following 3 URLs.

Remove video_player_upgrade.exe - Powered by Reason Core Security