GPlayer.exe

EXETender Client

Exent Technologies Ltd.

The application GPlayer.exe by Exent Technologies has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Exetender’. Additionally, the file is typically installed by a number of programs including Hoopla by Exent Technologies and Free Ride Games Player by Exent Technologies.
Publisher:
Exent Technologies Ltd.  (signed and verified)

Product:
EXETender™ Client

Description:
EXETender Player

Version:
07.03.55.00

MD5:
12a0947aec8adb713c8c8eb5aef1b020

SHA-1:
7a9e3c1bbccacee02feb0eaee198dd753e3c5cc0

SHA-256:
36a3f48b302472850a6ff1bf9cacd8c79f938ee8fbbd3e827bcd5a682cfba8a9

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
2/19/2018 9:18:06 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ExentTechnologies.H
14.5.3.16

File size:
4.7 MB (4,924,296 bytes)

Product version:
07.03.55.00

Copyright:
Copyright © 1996-2010 Exent Technologies Ltd. All rights reserved.

Original file name:
GPlayer.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\fantastigames\gplayer.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/19/2014 2:00:00 AM

Valid to:
5/19/2015 2:59:59 AM

Subject:
CN=Exent Technologies Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Exent Technologies Ltd., L=Petah-Tikva, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6B9F8042D6561C2EB1E66584D1341686

File PE Metadata
Compilation timestamp:
4/13/2014 6:30:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:Bnuk60mAN9TIK3srsmAaEBCGPqyF8sf1j8QX09wSlyDnUTFRIZDrjQYREQMOhKzx:tukNcrSaEXF8g14QMi8FRIZDrLEQMIM

Entry address:
0x20E2A1

Entry point:
55, 8B, EC, 6A, FF, 68, D8, 61, 7A, 00, 68, EC, 02, 61, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 60, 24, 79, 00, 33, D2, 8A, D4, 89, 15, CC, C1, 87, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, C8, C1, 87, 00, C1, E1, 08, 03, CA, 89, 0D, C4, C1, 87, 00, C1, E8, 10, A3, C0, C1, 87, 00, 6A, 01, E8, 0E, 63, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C2, 00, 00, 00, 59, E8, B9, 60, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B1, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
6.5574

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
3.6 MB (3,739,648 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Exetender

Command:
"C:\Program Files\fantastigames\gplayer.exe" \runonstartup


The file GPlayer.exe has been discovered within the following programs.

Free Ride Games Player  by Exent Technologies
Publisher's description - “FreeRide Games, operated by Exent, is the only 100% free online destination providing more than 400 premium full-download PC casual and online games. FreeRide Games remains the only website of its kind.”
55% remove it
Hoopla  by Exent Technologies
Display advertising. Form the EULA: "To create a more customized online experience for consumers, some of the ads you may receive on the Hoopla.com service are tailored to previous online behaviors/visits on your computer."
hoopla.com/tos
51% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to pr-bh.pbp.vip.bf1.yahoo.com  (72.30.2.182:443)

TCP (HTTP):

TCP (HTTP):
Connects to presentation-atl1.turn.com  (50.116.194.21:80)

TCP (HTTP):
Connects to m-prd-umpxl-shared-mr3-blue-a.evip.aol.com  (152.163.64.2:80)

TCP (HTTP):
Connects to a23-10-102-129.deploy.static.akamaitechnologies.com  (23.10.102.129:80)

TCP (HTTP):
Connects to um-21.btrll.com  (162.208.22.39:80)

TCP (HTTP SSL):
Connects to a23-56-194-57.deploy.static.akamaitechnologies.com  (23.56.194.57:443)

TCP (HTTP):

TCP (HTTP):
Connects to a.tribalfusion.com  (204.11.109.68:80)

TCP (HTTP):
Connects to tags.expo9.exponential.com  (204.11.109.78:80)

TCP (HTTP):
Connects to s3-1-w.amazonaws.com  (54.231.81.184:80)

TCP (HTTP SSL):
Connects to ox-173-241-244-143.lc.dc.openx.org  (173.241.244.143:443)

TCP (HTTP):
Connects to ec2-54-88-163-202.compute-1.amazonaws.com  (54.88.163.202:80)

TCP (HTTP):
Connects to ec2-54-243-174-106.compute-1.amazonaws.com  (54.243.174.106:80)

TCP (HTTP):
Connects to ec2-54-210-176-114.compute-1.amazonaws.com  (54.210.176.114:80)

TCP (HTTP):
Connects to ec2-52-7-230-255.compute-1.amazonaws.com  (52.7.230.255:80)

TCP (HTTP):
Connects to ec2-52-67-150-194.sa-east-1.compute.amazonaws.com  (52.67.150.194:80)

TCP (HTTP):
Connects to ec2-52-45-240-184.compute-1.amazonaws.com  (52.45.240.184:80)

TCP (HTTP):
Connects to ec2-177-71-203-84.sa-east-1.compute.amazonaws.com  (177.71.203.84:80)

TCP (HTTP):
Connects to ec2-174-129-235-214.compute-1.amazonaws.com  (174.129.235.214:80)

Remove GPlayer.exe - Powered by Reason Core Security