jjplayer2.7.2.7_setup.exe

JJVOD

Z.T.T SERVICE LTD PARTNERSHIP

The executable jjplayer2.7.2.7_setup.exe has been detected as malware by 7 anti-virus scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from dl.jijivod.com and multiple other hosts.
Publisher:
JJPlayer  (signed by Z.T.T SERVICE LTD PARTNERSHIP)

Product:
JJVOD

Version:
2.7.2.7

MD5:
f4ff51658d56e7bd3d9b7b7032c98913

SHA-1:
9729dfdcf616b852d1095696bd85b02df63bc978

SHA-256:
0361b43732791101493ccde8d714c43bf26cb0e409b1aadfa11b5f0453b13aa8

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/24/2024 6:14:32 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
ZTTService
2016.0.3150

Dr.Web
Trojan.Siggen6.22491
9.0.1.094

K7 AntiVirus
Riskware
13.202.15367

McAfee
Artemis!F4FF51658D56
5600.6806

NANO AntiVirus
Trojan.Win32.Siggen6.dnxcyh
0.30.8.659

Vba32 AntiVirus
Backdoor.DarkKomet
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
38742

File size:
23.2 MB (24,295,848 bytes)

Product version:
2.7.2.7

Copyright:
(C)jjvod.com Inc.All Rights Reserved.

Trademarks:
jjvod.com

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\jjplayer2.7.2.7_setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/8/2014 1:00:00 AM

Valid to:
4/8/2017 12:59:59 AM

Subject:
CN=Z.T.T SERVICE LTD PARTNERSHIP, OU=Marketing Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Z.T.T SERVICE LTD PARTNERSHIP, L=Bangkok, S=Bangkok, C=TH

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
364770D0B0B5C481EBEB677090A3F8EC

File PE Metadata
Compilation timestamp:
6/6/2009 10:44:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:k6WnDi2KUquPrfuiTy+9ipmsVPeoSe51eCpsrTn3KIqaBr2qdasOy611eXkH+Vr+:k7DiRUqkDZiheo15DgTn3KEBKqRQ1YO5

Entry address:
0x36A0

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 88, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, B8, 63, 42, 00, E8, EE, 2E, 00, 00, A3, 04, 63, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, B0, 0C, 42, 00, FF, 15, 58, 81, 40, 00, 68, 10, A8, 40, 00, 68, 00, 5B, 42, 00, E8, F4, 29, 00, 00, FF, 15, B0, 80, 40, 00, BF, 00, C0, 42, 00, 50, 57, E8, E2, 29, 00, 00...
 
[+]

Entropy:
7.9998

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file jjplayer2.7.2.7_setup.exe has been seen being distributed by the following 2 URLs.

http://dl.jijivod.com/JJPlayersetup_jjvod.exe

Remove jjplayer2.7.2.7_setup.exe - Powered by Reason Core Security