3.9.0.127_20140826040504.exe

The KMPlayer

Pandora TV Co., Ltd.

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from api2.tenlua.vn and multiple other hosts.
Publisher:
PandoraTV  (signed by Pandora TV Co., Ltd.)

Product:
The KMPlayer

Description:
The KMPlayer Setup/Install

Version:
3.9.0.127

MD5:
06687d29f9fd8f71343a5d6fa0657602

SHA-1:
be6f8b026d69a32bc370d723b166b2ff7199fd87

SHA-256:
9c4b3c5c4aeb753f8e4b91dafc6b1ba3ee028ad67b5029b6f33e72dff7158dd8

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/19/2024 8:28:54 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.5053
9.0.1.0240

Fortinet FortiGate
Riskware/OpenCandy
8/28/2014

Trend Micro House Call
Suspicious_GEN.F47V0826
7.2.240

File size:
31.3 MB (32,871,712 bytes)

Product version:
3.9

Copyright:
Copyright PandoraTV 2013.

Trademarks:
Freeware

Original file name:
KMPlayer_3.9.0.127.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Digital Signature
Authority:
Thawte, Inc.

Valid from:
5/12/2014 4:30:00 AM

Valid to:
5/12/2016 4:29:59 AM

Subject:
CN="Pandora TV Co., Ltd.", OU=IT Team, O="Pandora TV Co., Ltd.", L=Gangnam-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2670E850C13552677FC3CFBA525E11B8

File PE Metadata
Compilation timestamp:
2/24/2012 10:49:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
786432:KV3FlGHKZQJbyjh+fE/uP0uXcm/KrnqLkaz/aCSgMoPR/f42:KVxQtIh+M/uP01+Aaz2+Pb

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Entropy:
7.9999

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file 3.9.0.127_20140826040504.exe has been seen being distributed by the following 35 URLs.

http://api2.tenlua.vn/filemanager/builddownload/.../?hash=1578e073b70238465f3b382569ab2ad82c35f98ab14dac00bd328e659857431b622079f8e76d2fb11522fef211731b514a2815ceade24f2e6b5ec24bef9fd889da9afa988e5eddfaf6263606e8128665c4128021a5561e6e870032ce1b7c46c5f836a23e13037b82ea9fc668032cc176e74f97235906396a512126de90efeb3cf1c95b623b60f2d2366fc12880c729e7ab551284a4&url=0b3da36fa30172185e32336174fd75853636b390ad53eb4da0&down=0b3da36fa30172185e32336174fd75853636b390ad53fc55a0&jump_type=download&file=sinhvienit.net-kmplayer.3.9.0.127.exe

http://api2.tenlua.vn/filemanager/builddownload/.../?hash=5238e52bbb4b31004973642367fb7ddc7a36fed1a618f355bf2d9733d948494b622079f8e76d2fb11522fef211731b514a2815ceade24f2e6b5ec24bef9fd889da9afa988e5eddfaf6263606e8128665c4128021a5561e6e870032ce1b7c46c5f836a23e13037b82ea9fc668032cc176e74f97235906396a512126de90efeb3cf1c95b623b60f2d2366fc12880c729e7ab551284a4&url=0b3da36fa30172185e32336174fd75853636b390ad53eb4da0&down=0b3da36fa30172185e32336174fd75853636b390ad53fc55a0&jump_type=download&file=sinhvienit.net-kmplayer.3.9.0.127.exe

http://api2.tenlua.vn/filemanager/builddownload/.../?hash=1371a327be0f2b0f4a33392d75ea789c3163f488f34ced52ec3b93649956161f622079f8e76d2fb11522fef211731b514a2815ceade24f2e6b5ec24bef9fd889da9afa988e5eddfaf6263606e8128665c4128021a5561e6e870032ce1b7c46c5f836a23e13037b82ea9fc668032cc176e74f97235906396a512126de90efeb3cf1c95b623b60f2d2366fc12880c729e7ab551284a4&url=0b3da36fa30172185e32336174fd75853636b390ad53eb4da0&down=0b3da36fa30172185e32336174fd75853636b390ad53fc55a0&jump_type=download&file=sinhvienit.net-kmplayer.3.9.0.127.exe

http://api2.tenlua.vn/filemanager/builddownload/.../?hash=5b2aa36fa05832421e6a637e63ee718b336efad0a216fe5dfd609b65d8404913622079f8e76d2fb11522fef211731b514a2815ceade24f2e6b5ec24bef9fd889da9afa988e5eddfaf6263606e8128665c4128021a5561e6e870032ce1b7c46c5f836a23e13037b82ea9fc668032cc176e74f97235906396a512126de90efeb3cf1c95b623b60f2d2366fc12880c729e7ab551284a4&url=0b3da36fa30172185e32336174fd75853636b390ad53eb4da0&down=0b3da36fa30172185e32336174fd75853636b390ad53fc55a0&jump_type=download&file=sinhvienit.net-kmplayer.3.9.0.127.exe

http://download005.fshare.vn/dl/.../SinhvienIT.Net-KMPlayer.3.9.0.127.exe

http://api2.tenlua.vn/filemanager/builddownload/.../?hash=0f7cb279a0572d5b4a74642438ad7d8a2e67ae8ba74ba908bf36887f9f12440e622079f8e76d2fb11522fef211731b514a2815ceade24f2e6b5ec24bef9fd889da9afa988e5eddfaf6263606e8128665c4128021a5561e6e870032ce1b7c46c5f836a23e13037b82ea9fc668032cc176e74f97235906396a512126de90efeb3cf1c95b623b60f2d2366fc12880c729e7ab551284a4&url=0b3da36fa30172185e32336174fd75853636b390ad53eb4da0&down=0b3da36fa30172185e32336174fd75853636b390ad53fc55a0&jump_type=download&file=sinhvienit.net-kmplayer.3.9.0.127.exe

http://api2.tenlua.vn/filemanager/builddownload/.../?hash=1120e37dbe4d3e05446f6b2076e86d802b67af93ab1fac0cfd3a9139db4a461a622079f8e76d2fb11522fef211731b514a2815ceade24f2e6b5ec24bef9fd889da9afa988e5eddfaf6263606e8128665c4128021a5561e6e870032ce1b7c46c5f836a23e13037b82ea9fc668032cc176e74f97235906396a512126de90efeb3cf1c95b623b60f2d2366fc12880c729e7ab551284a4&url=0b3da36fa30172185e32336174fd75853636b390ad53eb4da0&down=0b3da36fa30172185e32336174fd75853636b390ad53fc55a0&jump_type=download&file=sinhvienit.net-kmplayer.3.9.0.127.exe

http://file.sinhvien.it/download/73c90c75/436c0a8d0ce37caf122f31ec3ca8d506/2014/.../SinhVienIT.Net--KMPlayer.3.9.0.127.exe

http://api2.tenlua.vn/filemanager/builddownload/.../?hash=072de77ce8586c51156c6b2c37fb68dd2121fa8db34cfa00e568cb3dda1f4c0b622079f8e76d2fb11522fef211731b514a2815ceade24f2e6b5ec24bef9fd889da9afa988e5eddfaf6263606e8128665c4128021a5561e6e870032ce1b7c46c5f836a23e13037b82ea9fc668032cc176e74f97235906396a512126de90efeb3cf1c95b623b60f2d2366fc12880c729e7ab551284a4&url=0b3da36fa30172185e32336174fd75853636b390ad53eb4da0&down=0b3da36fa30172185e32336174fd75853636b390ad53fc55a0&jump_type=download&file=sinhvienit.net-kmplayer.3.9.0.127.exe

http://download005.fshare.vn/dl/.../SinhvienIT.Net-KMPlayer.3.9.0.127.exe

http://api2.tenlua.vn/filemanager/builddownload/.../?hash=152ca476b5033904467371276bf72cdb7238f684ae13ee54b628c43fdf14440a622079f8e76d2fb11522fef211731b514a2815ceade24f2e6b5ec24bef9fd889da9afa988e5eddfaf6263606e8128665c4128021a5561e6e870032ce1b7c46c5f836a23e13037b82ea9fc668032cc176e74f97235906396a512126de90efeb3cf1c95b623b60f2d2366fc12880c729e7ab551284a4&url=0b3da36fa30172185e32336174fd75853636b390ad53eb4da0&down=0b3da36fa30172185e32336174fd75853636b390ad53fc55a0&jump_type=download&file=sinhvienit.net-kmplayer.3.9.0.127.exe

http://api2.tenlua.vn/filemanager/builddownload/.../?hash=083cb976a00f6559406b317d70fa2c8a2661aa81ae1fae4bfc3b9e78c1521947622079f8e76d2fb11522fef211731b514a2815ceade24f2e6b5ec24bef9fd889da9afa988e5eddfaf6263606e8128665c4128021a5561e6e870032ce1b7c46c5f836a23e13037b82ea9fc668032cc176e74f97235906396a512126de90efeb3cf1c95b623b60f2d2366fc12880c729e7ab551284a4&url=0b3da36fa30172185e32336174fd75853636b390ad53eb4da0&down=0b3da36fa30172185e32336174fd75853636b390ad53fc55a0&jump_type=download&file=sinhvienit.net-kmplayer.3.9.0.127.exe

http://api2.tenlua.vn/filemanager/builddownload/.../?hash=022cb529a10931051a35663d63fb759c2261f88ba014ee5dee6b99399d4a144c622079f8e76d2fb11522fef211731b514a2815ceade24f2e6b5ec24bef9fd889da9afa988e5eddfaf6263606e8128665c4128021a5561e6e870032ce1b7c46c5f836a23e13037b82ea9fc668032cc176e74f97235906396a512126de90efeb3cf1c95b623b60f2d2366fc12880c729e7ab551284a4&url=0b3da36fa30172185e32336174fd75853636b390ad53eb4da0&down=0b3da36fa30172185e32336174fd75853636b390ad53fc55a0&jump_type=download&file=sinhvienit.net-kmplayer.3.9.0.127.exe

http://file.dl1.svit.vn/download/73c90c75/ebe789c5cc8ea1a6aee385ae4e06213b/2014/.../SinhVienIT.Net--KMPlayer.3.9.0.127.exe

http://file.dl1.svit.vn/download/73c90c75/9503f35032ec007eee768cd48ead90d1/2014/.../SinhVienIT.Net--KMPlayer.3.9.0.127.exe

https://www.fshare.vn/.../TR9R5M03JT

http://ftp-stahuj.centrum.cz/dl/e11efb910ab5f5cb4438a5d36ac7b717/540f79a6/stahuj/download/software/secured/k/kmplayer/.../3.9.0.127_20140826040504.exe

http://www.afterdawn.com/software/.../download.cfm?version_id=87279&software_id=1240&mirror_id=0&installer=0&perion=0

http://api2.tenlua.vn/filemanager/builddownload/.../?hash=052da46bb2592b5b446d76286aa87e9f703ef094a54af748be348f619250470c622079f8e76d2fb11522fef211731b514a2815ceade24f2e6b5ec24bef9fd889da9afa988e5eddfaf6263606e8128665c4128021a5561e6e870032ce1b7c46c5f836a23e13037b82ea9fc668032cc176e74f97235906396a512126de90efeb3cf1c95b623b60f2d2366fc12880c729e7ab551284a4&url=0b3da36fa30172185e32336174fd75853636b390ad53eb4da0&down=0b3da36fa30172185e32336174fd75853636b390ad53fc55a0&jump_type=download&file=sinhvienit.net-kmplayer.3.9.0.127.exe

http://api2.tenlua.vn/filemanager/builddownload/.../?hash=0e21bb27b75069064b3134226ff7298d7560acd5a61efb0bf939913cda155219622079f8e76d2fb11522fef211731b514a2815ceade24f2e6b5ec24bef9fd889da9afa988e5eddfaf6263606e8128665c4128021a5561e6e870032ce1b7c46c5f836a23e13037b82ea9fc668032cc176e74f97235906396a512126de90efeb3cf1c95b623b60f2d2366fc12880c729e7ab551284a4&url=0b3da36fa30172185e32336174fd75853636b390ad53eb4da0&down=0b3da36fa30172185e32336174fd75853636b390ad53fc55a0&jump_type=download&file=sinhvienit.net-kmplayer.3.9.0.127.exe

Latest 30 of 35 download URLs

Scan 3.9.0.127_20140826040504.exe - Powered by Reason Core Security